Network Attack Analysis —
Classifying and Identifying Attack Patterns
With Textual Analysis Tools
The Plan
This set of pages describes an attempt
to characterize patterns of network attack.
The goal is to group attacks into similar patterns,
and ideally to automatically discover clusters of similar
patterns.
Similar attack patterns could suggest
similar origin or at least relation between
attacks widely separated in time and source.
Some tools used to estimate textual similarity can be applied
to the patterns to group attacks by similarity measure
and to classify a future attack as a member of a
previously seen category.
So, we need to look at a number of topics.
Each of these has its own page: