Multi-Resolution Analysis with Visualization to Determine Network Attack Patterns

Multi-Resolution Analysis with Visualization to Determine Network Attack Patterns
复制标题

DOI:
10.3390/app13063792
复制
发表时间:
2023-03
期刊:
影响因子:
--
通讯作者:
D. Jeong;Bong-Keun Jeong;Soo-Yeon Ji
D. Jeong;Bong-Keun Jeong;Soo-Yeon Ji
中科院分区:
--
文献类型:
--
作者:
D. Jeong;Bong-Keun Jeong;Soo-Yeon Ji

文献摘要

相似文献

分析网络流量活动是网络安全中检测攻击模式的必要条件。由于不断变化的计算环境和软件应用所引起的网络流量事件活动的复杂性,识别模式是具有挑战性的研究课题之一。本研究的重点是分析的有效性,结合多分辨率分析(MRA)和可视化识别网络流量活动的攻击模式。详细地说,离散小波变换(DWT)被用来从网络流量数据中提取特征,并研究其识别攻击的能力。为了提取特征,测试了各种滑动窗口和步长。然后,生成可视化以帮助用户进行交互式可视化分析,以识别异常网络流量事件。为了确定用于生成可视化的最佳解决方案,已经使用多个入侵检测数据集进行了广泛的评估。此外,使用三种不同的分类算法进行分类分析,以了解使用可视化MRA的有效性。从研究中,我们生成了与各种窗口和步长相关的多个可视化,以强调所提出的方法在通过形成独特的集群来区分正常和攻击事件方面的有效性。我们还发现,利用MRA与可视化通过生成清晰分离的视觉集群来提高网络入侵检测。
Analyzing network traffic activities is imperative in network security to detect attack patterns. Due to the complex nature of network traffic event activities caused by continuously changing computing environments and software applications, identifying the patterns is one of the challenging research topics. This study focuses on analyzing the effectiveness of integrating Multi-Resolution Analysis (MRA) and visualization in identifying the attack patterns of network traffic activities. In detail, a Discrete Wavelet Transform (DWT) is utilized to extract features from network traffic data and investigate their capability of identifying attacks. For extracting features, various sliding windows and step sizes are tested. Then, visualizations are generated to help users conduct interactive visual analyses to identify abnormal network traffic events. To determine optimal solutions for generating visualizations, an extensive evaluation with multiple intrusion detection datasets has been performed. In addition, classification analysis with three different classification algorithms is managed to understand the effectiveness of using the MRA with visualization. From the study, we generated multiple visualizations associated with various window and step sizes to emphasize the effectiveness of the proposed approach in differentiating normal and attack events by forming distinctive clusters. We also found that utilizing MRA with visualization advances network intrusion detection by generating clearly separated visual clusters.