A flow analysis for mining traffic anomalies

Yoshiki Kanda*, Kensuke Fukuda, Toshiharu Sugawara

*この研究の対応する著者

研究成果: Conference contribution

12 被引用数 (Scopus)

抄録

Although analyzing anomalous network traffic behavior is a popular research topic, few studies have been undertaken on the analysis of communication pattern per host based on their flows to characterize the anomalous Internet traffic. This paper discusses the possibility of using a flow-based communication pattern per host as a metric to identify anomalies. The key idea underlining our method is that scanning worm-infected hosts reveal the intrinsic characteristics of host's communication pattern and such patterns are distinguishable from those of other hosts. In particular, we found that scanning of worm-infected hosts that generated a lot of flows revealed the intrinsic communication pattern and the pattern could be classified from those of other hosts by k-means clustering.We also found that our flow-based metric could isolate the anomalies that have little influence upon the volumetric information of traffic and flow as "lines", which is remarkable in that the hosts that caused the hidden anomalies were mined out.

本文言語English
ホスト出版物のタイトル2010 IEEE International Conference on Communications, ICC 2010
DOI
出版ステータスPublished - 2010
イベント2010 IEEE International Conference on Communications, ICC 2010 - Cape Town, South Africa
継続期間: 2010 5月 232010 5月 27

出版物シリーズ

名前IEEE International Conference on Communications
ISSN(印刷版)0536-1486

Conference

Conference2010 IEEE International Conference on Communications, ICC 2010
国/地域South Africa
CityCape Town
Period10/5/2310/5/27

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • 電子工学および電気工学

フィンガープリント

「A flow analysis for mining traffic anomalies」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル