SLIDE 30 Problem definition Clustering Detection Measurements Result analysis Future work
0.12 0.125 0.13 0.135 0.14 0.145 0.15 0.155 0.16 0.165 0.75 0.76 0.77 0.78 0.79 0.8 0.81 0.82 0.83
False Positive True Positive Performance Curve FP: 0.1205, TP: 0.7531 FP: 0.1647, TP: 0.8122 FP: 0.1597, TP: 0.8093
(a) Performance curve for DV A composed of validating and frequently-changing hosts.
0.01 0.03 0.05 0.07 0.09 0.11 0.13 0.15 0.17 0.19 0.21 0.23 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9
False Positive True Positive Performance Curve FP: 0.0271, TP: 0.2018 FP: 0.2228, TP: 0.8489 FP: 0.2029, TP: 0.8280
(b) Performance curve for DV A composed of validating and rarely-changing hosts. Figure: Performance of the detection measurements against two attacking strategies: frequently-changing (7a), and rarely-changing(7b).
Chwalinski, Belavkin, Xiaochun Detection of HTTP-GET Attack