Content area

Abstract

The South African National Research and Education Network (SA NREN) proves network connectivity and services to all tertiary education networks and research councils within South Africa. The NREN forms part of South Africa's national integrated cyber infrastructure, as such, it is a potential target for cyber-attacks. Due to the large volume of traffic and decentralised nature of the SA NREN, monitoring, reporting and mitigating cyber-attacks is a complex problem. The NREN Cyber Incident Response Team (CSIRT) uses network flow data to identify early indicators of cyber-attacks. In this paper the focus will be on the mechanisms used to identify malicious botnet traffic using network flow analysis.

Full text

Turn on search term navigation

Copyright Academic Conferences International Limited Jun 2020