eldorado.tu-dortmund.de/server/api/core/bitstreams/58953e56-2602-445c-9d85-b32666ab788c/content
Web-Authentisierung mit dem ePA
payload), ... }
{ (t, sIP, dIP, sp, dp, l7proto, payload, ...), ... }
{ (t, sIP, dIP, sp, dp, bSent, bRcvd, duration, l7msgsSent, l7msgsRcvd, entropy, l7proto, dnsResolvedDst, dnsFailureRate, ...), ... }
Depends [...] (sFlow similar)
10
Frame
Flow
1
n
{ (t, srcMac, dstMac, l3proto, payload), ... }
{ (t, sIP, dIP, sp, dp, bSent, bRcvd, duration), ... }
t=timestamp, sp=src port, dp=dst port, bSent=bytes sent, bRcvd=bytes [...] Detection should be based on any kind of traffic that is present even if no attack takes place, such as C&C traffic
Attack traffic may support detection
6
2. Discussion of approaches
7
Approach: Flow …