Towards Early Detection Of Novel Attack Patterns Through The Lens Of A Large-Scale Darknet

2016 INT IEEE CONFERENCES ON UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING AND COMMUNICATIONS, CLOUD AND BIG DATA COMPUTING, INTERNET OF PEOPLE, AND SMART WORLD CONGRESS (UIC/ATC/SCALCOM/CBDCOM/IOP/SMARTWORLD)(2016)

引用 15|浏览19
暂无评分
摘要
Darknet monitoring provides a cost-effective way to monitor the global trend of cyber-threats in the Internet. To make full use of the darknet traffic at hand, in this paper, we present a study on early detection of emerging novel attacks observed in the darknet. First, exploration of the regularities in the communications from attacking hosts are done by feeding all observed packets in the darknet to a frequent itemset mining engine, where the most frequently occurred attack patterns are automatically grouped together. Second, a time series which characterizes the activity level of each attack pattern is created over the observation period. Then, to extract the most prominent attack patterns, a clustering algorithm is engaged to cluster the attack patterns into groups that carry the similar activities in a long run and dimension reduction is employed to provide visual hints about their relationship. Finally, attacks featured by a recent rapid increase are picked up to be further inspected by security experts for incident handling purpose. The experiments show that the proposed scheme is effective and efficient in early detection of new attack patterns from conventional approaches.
更多
查看译文
关键词
Cybersecurity,Network traffic analysis,darknet analysis,association rule mining
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要