Anomaly detection tool based on network behavior profiles
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14610%2F11%3A00050711" target="_blank" >RIV/00216224:14610/11:00050711 - isvavai.cz</a>
Result on the web
<a href="http://www.muni.cz/ics/research/cyber/anomaly_detection" target="_blank" >http://www.muni.cz/ics/research/cyber/anomaly_detection</a>
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
Anomaly detection tool based on network behavior profiles
Original language description
Anomaly detection tool based on network behavior profiles is a set of specialized scripts to transform NetFlow statistics and process them as time series. First a behavior profiles for set of IP addresses are created using nfdump tools. The subsequent processing is performed in system R using Holt-Winters data analysis method. In case of anomaly detection an event is generated and stored in specified log file. The anomaly detection tool also includes connector to use pre-computed behavior profiles stored in relational database.
Czech name
—
Czech description
—
Classification
Type
R - Software
CEP classification
IN - Informatics
OECD FORD branch
—
Result continuities
Project
<a href="/en/project/OVMASUN200801" target="_blank" >OVMASUN200801: Security of Czech army information and communication systems - On-line monitoring, Visualization and Packet Filtration. Computer Incident Response Capability Development in the Cyber Defence Environment.</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2011
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Internal product ID
anomalydet
Technical parameters
Odpovědná osoba: Jan Pavlovič, Masarykova univerzita, Centrum pro transfer technologií, Žerotínovo nám. 9, 601 77 Brno, tel.: +420 549 49 8016, e-mail: ctt@ctt.muni.cz
Economical parameters
volně dostupný softwarový prostředek, ekonomický přínos nelze vyčíslit
Owner IČO
00216224
Owner name
Masarykova univerzita