Detecção de ataques de negativa de serviço por meio de fluxos de dados e sistemas inteligentes

Adriano M. CansianJorge L. Corrêa

This article presents a new model to anomalies and intrusion attempts detection based on the use of network flows (Netflow standard) and in the classification capacity of the artificial neural networks. The model is characterized by the behavior based detection of network environment together with the capacity of knowledge absorption of the intelligent systems. A new concept of signature is used, being tested several models along the evolution of the system. Several attacks like DoS, DDoS and worms activities are detected quickly, in a scalable and automated way for medium and big load environment, characterizing an effective monitor model for networks connected to the Internet.

