思科ETA主頁
https://www.cisco.com/c/en/us/solutions/enterprise-networks/enterprise-network-security/eta.html
ETA有關開源項目:
https://github.com/cisco/joy/tree/master/src
ETA數據分析思路:
Understanding Network Traffic Through Intraflow Data
https://resources.sei.cmu.edu/asset_files/Presentation/2016_017_001_450411.pdf
白皮書:
https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/enterprise-network-security/nb-09-encrytd-traf-anlytcs-wp-cte-en.pdf
other:
https://apjc.thecisconetwork.com/site/content/lang/en/id/7905
思科ETA提取的元數據:
相關知識, 什么是信息熵?
https://www.zhihu.com/question/22178202
放在現在這個信息時代,其實信息熵的概念一句話就能概括:
一個東西的信息熵(信息量),就是把這個東西存在你硬盤上所需要的最小空間。”