This set of pages describes an attempt to characterize patterns of network attack. The goal is to group attacks into similar patterns, and ideally to automatically discover clusters of similar patterns. Similar attack patterns could suggest similar origin or at least relation between attacks widely separated in time and source.
Some tools used to estimate textual similarity can be applied to the patterns to group attacks by similarity measure and to classify a future attack as a member of a previously seen category.
So, we need to look at a number of topics. Each of these has its own page:
|
Next: The Background of the Threat |
|
| Back to the start: The main page | |
|
||||||||||||
|
||||||||||||