Internet Traffic Behavior Profiling for Network Security Monitoring

Internet Traffic Behavior Profiling for Network Security Monitoring
复制标题

DOI:
10.1109/tnet.2007.911438
复制
发表时间:
2008-12
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Kuai Xu;Zhi-Li Zhang;S. Bhattacharyya
Kuai Xu;Zhi-Li Zhang;S. Bhattacharyya
中科院分区:
其他
文献类型:
--
作者:
Kuai Xu;Zhi-Li Zhang;S. Bhattacharyya

文献摘要

被引文献

相似文献

最近大量的网络攻击和频繁出现的影响互联网流量动态的应用程序使得开发有效的技术势在必行,这些技术可以从互联网流量数据中提取和理解重要的通信模式,用于网络运营和安全管理。在本文中,我们提出了一种从终端主机和服务的通信模式角度构建互联网骨干网流量综合行为概况的一般方法。该方法依靠数据挖掘和基于熵的技术,包括重要的聚类提取、自动行为分类和结构建模,以进行深入的解释分析。我们使用来自互联网核心的数据集来验证方法。
Recent spates of cyber-attacks and frequent emergence of applications affecting Internet traffic dynamics have made it imperative to develop effective techniques that can extract, and make sense of, significant communication patterns from Internet traffic data for use in network operations and security management. In this paper, we present a general methodology for building comprehensive behavior profiles of Internet backbone traffic in terms of communication patterns of end-hosts and services. Relying on data mining and entropy-based techniques, the methodology consists of significant cluster extraction, automatic behavior classification and structural modeling for in-depth interpretive analyses. We validate the methodology using data sets from the core of the Internet.