1,720,980 research outputs found

    Discovery of DoS attacks by the ZED-IDS anomaly detector

    No full text
    Intrusion detection is one of the major challenges in today's security industry. Currently attack surfaces are more extensive than in the past, and the use of anomaly detection tools, able to detect intrusions and malicious activities, is essential to avoid infrastructure damages. Furthermore, attackers are able to exploit techniques that bypass security countermeasures and avoid straight detection. Machine learning techniques are widely used to perform effective intrusion detection. In this context, deep learning networks may play an important role, by analyzing network flows and classifying them as 'normal' or 'intrusion'. This paper presents a deep learning architecture for DoS attacks detection, which is the first result of an on-going project aiming at the design and implementation of tools for the detection of 0-day threats (ZED-IDS, Zero Day Intrusion Detection System). The problem is tackled as a semi-supervised task, and the anomaly detector is based on a deep autoencoder. The model is described, and the detection performance results obtained on the CICIDS2017 dataset are presented and commented. The performance comparison with the most common supervised classifiers shows the potential of the proposal for 0-day attack detection

    Demystifying the role of public intrusion datasets: A replication study of DoS network traffic data

    No full text
    Public intrusion datasets are contributing to make security research accessible to a large community of users, but are often trusted and reused neglecting the actual impact of the attacks therein on victim services. This paper documents a study aimed to assess whether the attacks provided by public datasets are impactful on their targets. DoS traffic data from five public datasets (CICIDS2017, ISCXIDS2012, NDSec-1 2016, MILCOM 2016 and SUEE 2017) are replayed, monitoring the performance of the victim server under different defense, configuration and load conditions. The obtained results show a partial ineffectiveness of the attacks of the datasets in the presence of defense mechanisms and suitable server configurations. These results pave the way for the construction of more rigorous datasets, collected on documented and realistic server configurations and reflecting actual traffic conditions under normative operations and disruptive attacks

    Black-box load testing to support auto-scaling web applications in the cloud

    No full text
    One of the most interesting features of cloud environments is the possibility to deploy scalable applications, which can automatically modulate the amount of leased resources so as to adapt to load variations and to guarantee the desired level of quality of service. As auto-scaling has severe implications on execution costs, making optimal choices is of paramount importance. This paper presents a method based on off-line black-box load testing that allows to obtain performance indexes of a web application in multiple configurations under realistic load. These indexes, along with available resource cost information, can be exploited by auto-scaler tools to implement the desired scaling policy, making a trade-off between cost and user-perceived performance

    A case study on the representativeness of public DoS network traffic data for cybersecurity research

    No full text
    The availability of ready-to-use public security datasets is fostering measurement-driven research by a wide community of academics and practitioners. Recent trends in this area put forth a substantial body of literature on anomaly and attack detection on the top of public labelled datasets. Much of this literature blindly reuses existing datasets by overlooking the cybersecurity facets of the network traffic therein, in terms of its real impact on service availability and performance of operations. This paper addresses the representativeness of network traffic data provided by public datasets for cybersecurity research. To this aim, it proposes an initial exploration of the topic by means of a case study on Denial of Service (DoS) traffic of CICIDS2017, which is a recent dataset collected in a controlled environment that gained massive attention over the past two years. DoS traffic, which is available in CICIDS2017 in the form of packet data files, is replayed against a victim server in a controlled testbed. Measurements indicate that the DoS traffic, although somewhat relevant at network-level, has limited impact at application-level (i.e., by taking into account the performance of the victim under attack). The findings provide some key insights into the limitations of the data assessed in the study, paving the way for the construction of more rigorous datasets conceived with a multilayer perspective and that reflect actual traffic conditions under normative operations and disruptive attacks

    Auto-scaling Applications in the Cloud by Simple Indexes with Complex Loads

    No full text
    Applications executed in the cloud can exploit its elasticity features, varying dynamically the amount of leased resources so as to adapt to load variations and to guarantee quality of service. As auto-scaling has implications on execution costs, making optimal scaling choices is of paramount importance. This paper presents an analysis method based on offline benchmarking and simple models that allows to evaluate performance indexes useful to define scaling policies to be used by auto-scalers. The proposed approach relies on a fixed set of benchmarks, to be executed off-line and a set of models that enable prediction of the same performance indexes under different workload conditions, enabling the analyst to perform parameter analysis when defining an auto-scaling policy

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
    corecore