A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2015; you can also visit the original URL.
The file type is application/pdf
.
Detecting, validating and characterizing computer infections in the wild
2011
Proceedings of the 2011 ACM SIGCOMM conference on Internet measurement conference - IMC '11
Although network intrusion detection systems (IDSs) have been studied for several years, their operators are still overwhelmed by a large number of false-positive alerts. In this work we study the following problem: from a large archive of intrusion alerts collected in a production network, we want to detect with a small number of false positives hosts within the network that have been infected by malware. Solving this problem is essential not only for reducing the falsepositive rate of IDSs,
doi:10.1145/2068816.2068820
dblp:conf/imc/RaftopoulosD11
fatcat:hkbkyyuuwjamxi2gnk77wygoaa