Abstract
Network forensics known as an extended phase of network security plays an essential role in dealing with cybercrime. The performance of a network forensics system heavily depends on the network attack detection solutions. Two main types of network attacks are network level and application level. Current research methods have improved the detection rate but this is still a challenge. We propose a Shannon entropy approach to this study to identify executable file content for anomaly-based network attack detection in network forensics systems. Experimental results show that the proposed approach provides high detection rate
| Original language | English |
|---|---|
| Title of host publication | International Conference on Network and System Security (NSS 2014) |
| Editors | Man Ho Au, Barbara Carminati, C.-C Jay Kuo |
| Place of Publication | Germany |
| Publisher | Springer |
| Pages | 510-517 |
| Number of pages | 8 |
| Volume | 8792 |
| ISBN (Electronic) | 9783319116983 |
| ISBN (Print) | 9783319116976 |
| DOIs | |
| Publication status | Published - 2014 |
| Event | The 8th International Conference on Network and System Security 2014 - Xian, Xian, China Duration: 15 Oct 2014 → 17 Oct 2014 |
Publication series
| Name | Lecture Notes in Computer Science |
|---|---|
| Publisher | Springer |
| Volume | 8792 |
| ISSN (Print) | 0302-9743 |
Conference
| Conference | The 8th International Conference on Network and System Security 2014 |
|---|---|
| Country/Territory | China |
| City | Xian |
| Period | 15/10/14 → 17/10/14 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 16 Peace, Justice and Strong Institutions
Fingerprint
Dive into the research topics of 'A new approach to executable file fragment detection in network forensics'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver