The Johns Hopkins University Applied Physics Laboratory
被引用7|浏览9
摘要
This paper describes our initial results achieved using an unsupervised approach for finding suspicious behavior in enterprise networks. We are using sequential pattern mining (SPM) to extract sequences of events for all IPs in a network. The premise of this work is that sequences which describe malicious behavior will be rare. To our knowledge there are no other works that use SPM to identify malicious behavior in Common Event Format (CEF) datasets of the type we are using. Our initial results show promise: when the sequences are built per source IP a cyber analyst would have to look at less than 0.4% of all IPs in order to find all the malicious ones.