Authors
George Stergiopoulos, Georgia Chronopoulou, Evangelos Bitsikas, Nikolaos Tsalis, Dimitris Gritzalis
Publication date
2019
Journal
Journal of Computer Security
Issue
Preprint
Pages
1-14
Publisher
IOS Press
Description
During the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university …
Total citations
201920202021202220232024132123
Scholar articles
G Stergiopoulos, G Chronopoulou, E Bitsikas, N Tsalis… - Journal of Computer Security, 2019