Structure-based Data Mining and Screening for Network Traffic Data

Structure-based Data Mining and Screening for Network Traffic Data
复制标题

基于结构的网络流量数据挖掘与筛选

DOI:
10.1109/iiai-aai.2013.78
复制
发表时间:
2013
期刊:
Proc. 2nd Int. Conf. Advanced Applied Informatics (IIAI-AAI2013)
影响因子:
--
通讯作者:
H. Tsuruta and T . Shoudai
H. Tsuruta and T . Shoudai
中科院分区:
--
文献类型:
--
作者:
Hiroshi Hirai;Shigeru Takano;Einoshin Suzuki;H. Tsuruta and T . Shoudai

文献摘要

相似文献

暗网监测对于了解各种僵尸网络活动,以便早期检测由僵尸网络引起的互联网威胁起着重要作用。然而,普通恶意软件的常见非法访问使得这种检测变得困难。为了从网络监控结果中删除普通恶意软件的访问,Tsuruta等人(2012)提出了一种自动数据筛选方法,通过发现观察到的网络流量数据中出现的频繁字符串模式。本文提出了一种基于2-边连通二部图结构的数据挖掘和筛选方法。我们将我们的方法应用于暗网中观察到的网络流量数据,并报告了结果。
Darknet monitoring plays an important role for understanding various botnet activities for early detection of the threats on the Internet caused by the botnets. However, common illegal accesses by ordinary malware make such detection difficult. To remove such accesses by ordinary malware from the results of network monitoring, Tsuruta et al. (2012) proposed an automatic data screening method by discovering frequent string-based patterns appearing in observed network traffic data. In this paper, we propose a data mining and screening method based on 2-edge-connected bipartite graph structures. We applied our method to network traffic data observed in the darknet and report the results.