TY - JOUR AU - Lu, Jiazhong AU - Lv, Fengmao AU - Zhuo, Zhongliu AU - Zhang, Xiaosong AU - Liu, Xiaolei AU - Hu, Teng AU - Deng, Wei PY - 2019 DA - 2019/06/13 TI - Integrating Traffics with Network Device Logs for Anomaly Detection SP - 5695021 VL - 2019 AB - Advanced cyberattacks are often featured by multiple types, layers, and stages, with the goal of cheating the monitors. Existing anomaly detection systems usually search logs or traffics alone for evidence of attacks but ignore further analysis about attack processes. For instance, the traffic detection methods can only detect the attack flows roughly but fail to reconstruct the attack event process and reveal the current network node status. As a result, they cannot fully model the complex multistage attack. To address these problems, we present Traffic-Log Combined Detection (TLCD), which is a multistage intrusion analysis system. Inspired by multiplatform intrusion detection techniques, we integrate traffics with network device logs through association rules. TLCD correlates log data with traffic characteristics to reflect the attack process and construct a federated detection platform. Specifically, TLCD can discover the process steps of a cyberattack attack, reflect the current network status, and reveal the behaviors of normal users. Our experimental results over different cyberattacks demonstrate that TLCD works well with high accuracy and low false positive rate. SN - 1939-0114 UR - https://doi.org/10.1155/2019/5695021 DO - 10.1155/2019/5695021 JF - Security and Communication Networks PB - Hindawi KW - ER -