86 research outputs found
Un système de surveillance et détection de menaces utilisant le traitement de flux comme une fonction virtuelle pour le Big Data
The late detection of security threats causes a significant increase in the risk of irreparable damages, disabling any defense attempt. As a consequence, fast real-time threat detection is mandatory for security administration. In addition, Network Function Virtualization (NFV) provides new opportunities for efficient and low-cost security solutions. We propose a fast and efficient threat detection system based on stream processing and machine learning algorithms. The main contributions of this work are i) a novel monitoring threat detection system based on streaming processing, ii) two datasets, first a dataset of synthetic security data containing both legitimate and malicious traffic, and the second, a week of real traffic of a telecommunications operator in Rio de Janeiro, Brazil, iii) a data pre-processing algorithm, a normalizing algorithm and an algorithm for fast feature selection based on the correlation between variables, iv) a virtualized network function in an Open source Platform for providing a real-time threat detection service, v) near-optimal placement of sensors through a proposed heuristic for strategically positioning sensors in the network infrastructure, with a minimum number of sensors, and finally vi) a greedy algorithm that allocates on demand a sequence of virtual network functions.La détection tardive des menaces à la sécurité entraîne une augmentation significative du risque de dommages irréparables, invalidant toute tentative de défense. En conséquence, la détection rapide des menaces en temps réel est obligatoire pour l'administration de la sécurité. De plus, la fonction de virtualisation de la fonction réseau (NFV) offre de nouvelles opportunités pour des solutions de sécurité efficaces et à faible coût. Nous proposons un système de détection de menaces rapide et efficace basé sur des algorithmes de traitement de flux et d'apprentissage automatique. Les principales contributions de ce travail sont : i) un nouveau système de détection des menaces de surveillance basé sur le traitement en continu, ii) deux ensembles de données, d'abord un ensemble de données de sécurité synthétiques contenant à la fois du trafic légitime et malveillant, et le deuxième, une semaine de trafic réel d'un opérateur de télécommunications à Rio de Janeiro, au Brésil, iii) un algorithme de pré-traitement de données, un algorithme de normalisation et un algorithme de sélection de caractéristiques rapides basé sur la corrélation entre des variables, iv) une fonction de réseau virtualisé dans une plate-forme Open Source pour fournir un service de détection des menaces en temps réel, v) placement quasi-optimal des capteurs grâce à une heuristique proposée pour positionner stratégiquement les capteurs dans l'infrastructure du réseau, avec un nombre minimal de capteurs, et enfin vi) un algorithme glouton qui alloue à la demande une séquence de fonctions de réseau virtuel
Manufacturing Agrarian Change - Agricultural production, inter-sectoral learning and technological capabilities
The aim of this paper is to investigate how industrial development, manufacturing in particular, has been contributing to agrarian change. In order to address this issue, it analyzes the technical bases and structural specificities – i.e. time and scale constraints – of agricultural production. Technical change in agriculture involves both improvements in organic transformation processes – i.e. biological production – and in the mechanical functions that have to be performed for obtaining a certain output – i.e. agricultural work. The paper shows how in-farm technological capabilities building as well as inter-sectoral learning are necessary in order to acquire and adapt biological-chemical innovations and mechanical technologies. The analysis of agrarian technical change – both in-farm learning and inter-sectoral learning – is developed by integrating peasant studies with evolutionary approaches to economic development. The relationship between agrarian change and manufacturing development is highly context specific, thus comparative historical analysis is adopted in order to shed light on the abovementioned processes of learning. Building on the analysis of technological change in agriculture, the last part of the paper will focus on those transformative policies such as innovative ‘extension services’ which facilitate inter-sectoral learning and, in turn, allow the emergence of inter-sectoral commons. This concept identifies that specific bundle of technological capabilities which concentrate in certain areas of strong inter-sectoral interdependence as a result of inter-sectoral learning.
A monitoring and threat detection system using stream processing as a virtual function for Big Data
La détection tardive des menaces à la sécurité entraîne une augmentation significative du risque de dommages irréparables, invalidant toute tentative de défense. En conséquence, la détection rapide des menaces en temps réel est obligatoire pour l'administration de la sécurité. De plus, la fonction de virtualisation de la fonction réseau (NFV) offre de nouvelles opportunités pour des solutions de sécurité efficaces et à faible coût. Nous proposons un système de détection de menaces rapide et efficace basé sur des algorithmes de traitement de flux et d'apprentissage automatique. Les principales contributions de ce travail sont : i) un nouveau système de détection des menaces de surveillance basé sur le traitement en continu, ii) deux ensembles de données, d'abord un ensemble de données de sécurité synthétiques contenant à la fois du trafic légitime et malveillant, et le deuxième, une semaine de trafic réel d'un opérateur de télécommunications à Rio de Janeiro, au Brésil, iii) un algorithme de pré-traitement de données, un algorithme de normalisation et un algorithme de sélection de caractéristiques rapides basé sur la corrélation entre des variables, iv) une fonction de réseau virtualisé dans une plate-forme Open Source pour fournir un service de détection des menaces en temps réel, v) placement quasi-optimal des capteurs grâce à une heuristique proposée pour positionner stratégiquement les capteurs dans l'infrastructure du réseau, avec un nombre minimal de capteurs, et enfin vi) un algorithme glouton qui alloue à la demande une séquence de fonctions de réseau virtuel.The late detection of security threats causes a significant increase in the risk of irreparable damages, disabling any defense attempt. As a consequence, fast real-time threat detection is mandatory for security administration. In addition, Network Function Virtualization (NFV) provides new opportunities for efficient and low-cost security solutions. We propose a fast and efficient threat detection system based on stream processing and machine learning algorithms. The main contributions of this work are i) a novel monitoring threat detection system based on streaming processing, ii) two datasets, first a dataset of synthetic security data containing both legitimate and malicious traffic, and the second, a week of real traffic of a telecommunications operator in Rio de Janeiro, Brazil, iii) a data pre-processing algorithm, a normalizing algorithm and an algorithm for fast feature selection based on the correlation between variables, iv) a virtualized network function in an Open source Platform for providing a real-time threat detection service, v) near-optimal placement of sensors through a proposed heuristic for strategically positioning sensors in the network infrastructure, with a minimum number of sensors, and finally vi) a greedy algorithm that allocates on demand a sequence of virtual network functions
Bibliographics for the 983 eprints in the live archives of E-LIS : trends and status report up to 7th July 2004, based on author-self-archiving metadata
The priority for ideas and philosophy related to "Network Theory" have been traced back and documented by Braun(2004),and credit goes to Karinthy(1929).The IT has empowered to realise it, as the most practical phenomena and it is no more a humour. The OAI (Open Archives Initiatives)and ACIS (Academic Contributor Information System)are progressive in the direction ,which may lead to realise the "Collective Genius" at global level. Focus of present study is on Author-Self-Archiving (A-S-A)Metadata of the 983 Eprints in the Live Archives of the E-LIS (EPrints of Library and Information Science),which were approved till 7th July 2004.The A-S-A Metadata was used for librametric analysis. Self-explanatory bibliographics are illustrated.The highlights include: Conference papers (34%); highest approval, June 2004 (28%); published archives (76%);not refereed (52%); not in public domain (60%); highest self-archiving-author (De Robbio, Antonella).The Nos. of EPrints having single JITA domain specifications were: Theoretical and general aspects of libraries and information(27); Information use and sociology of information(80);Users,literacy and reading(13);Libraries as physical collections(30);Publishing and legal issues(57);Management(13);Industry, profession and education(36);Information sources, supports, channels(113) ; Information treatment for information services, Information functions and techniques (101); Technical services libraries, archives and museums(25); Housing technologies(1); Information technology and library technology(92); and Inter-domainery (395) i.e. having specifications of two or more than two JITA classes
Providing elasticity to intrusion detection systems in virtualized Software Defined Networks
ARCADE: Adversarially Regularized Convolutional Autoencoder for Network Anomaly Detection
As the number of heterogenous IP-connected devices and traffic volume
increase, so does the potential for security breaches. The undetected
exploitation of these breaches can bring severe cybersecurity and privacy
risks. Anomaly-based \acp{IDS} play an essential role in network security. In
this paper, we present a practical unsupervised anomaly-based deep learning
detection system called ARCADE (Adversarially Regularized Convolutional
Autoencoder for unsupervised network anomaly DEtection). With a convolutional
\ac{AE}, ARCADE automatically builds a profile of the normal traffic using a
subset of raw bytes of a few initial packets of network flows so that potential
network anomalies and intrusions can be efficiently detected before they cause
more damage to the network. ARCADE is trained exclusively on normal traffic. An
adversarial training strategy is proposed to regularize and decrease the
\ac{AE}'s capabilities to reconstruct network flows that are out-of-the-normal
distribution, thereby improving its anomaly detection capabilities. The
proposed approach is more effective than state-of-the-art deep learning
approaches for network anomaly detection. Even when examining only two initial
packets of a network flow, ARCADE can effectively detect malware infection and
network attacks. ARCADE presents 20 times fewer parameters than baselines,
achieving significantly faster detection speed and reaction time
A Monitoring and Threat Detection System Using Stream Processing as a Virtual Function for Big Data
Toward a monitoring and threat detection system based on stream processing as a virtual network function for big data
International audienceThe late detection of security threats causes a significant increase in the risk of irreparable damages and restricts any defense attempt. In this paper, we propose a sCAlable TRAffic Classifier and Analyzer (CATRACA). CATRACA works as an efficient online Intrusion Detection and Prevention System implemented as a Virtualized Network Function. CATRACA is based on Apache Spark, a Big Data Streaming processing system, and it is deployed over the Open Platform for Network Functions Virtualization (OPNFV), providing an accurate real‐time threat‐detection service. The system presents a friendly graphical interface that provides real‐time visualization of the traffic and the attacks that occur in the network. Our prototype can differentiate normal traffic from denial of service (DoS) attacks and vulnerability probes over 95% accuracy under three different datasets. Moreover, CATRACA handles streaming data under concept drift detection with more than 85% of accuracy
An evaluation of a virtual network function for real-time threat detection using stream processing
International audienceNetwork Function Virtualization (NFV) provides new opportunities for efficient and low-cost security solutions. Real-time traffic monitoring and fast security threat detection is a challenge to reduce the risk of great damages. In this paper, we propose a virtualized network function in an Open Source Platform for providing a real-time threat detection service. Our function combines cloud computing and distributed stream processing techniques to accurately and quickly detect threats. The proposed virtualized network function shows a good elasticity shrinking and scaling accordingly to the required load. The results show that the proposed function is able to scale dynamically, analyzing more than five million messages per second. In addition, the function easily migrates sensor elements to reduce latency, allowing the sensor to be located as near as possible to the client
Attackers are not Stealthy: Statistical Analysis of the Well-Known and Infamous KDD Network Security Dataset
- …
