Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. Relational network-service clustering analysis with set evidences
 
conference paper

Relational network-service clustering analysis with set evidences

Pu, L.
•
Faltings, B.  
•
Yang, Q.
Show more
2010
Proceedings of the ACM Conference on Computer and Communications Security
The 3rd Workshop on Artificial Intelligence and Security

Network administrators are faced with a large amount of network data that they need to sift through to analyze user behaviors and detect anomalies. Through a network monitoring tool, we obtained TCP and UDP connection records together with additional information of the associated users and software in an enterprise network. Instead of using traditional payload inspection techniques, we propose a method that clusters such network traffic data by using relations between entities so that it can be analyzed for frequent behaviors and anomalies. Relational methods like Markov Logic Networks is able to avoid the feature extraction stage and directly handle multi-relation situations. We extend the common pairwise representation in relational models by adopting set evidence to build a better objective for the network service clustering problem. The automatic clustering process helps the administrator filter out normal traffic in shorter time and get an abstract overview of opening transport layer ports in the whole network, which is beneficial for assessing network security risks. Experimental results on synthetic and real datasets suggest that our method is able to discover underlying services and anomalies (malware or abused ports) with good interpretations. © 2010 ACM.

  • Files
  • Details
  • Metrics
Loading...
Thumbnail Image
Name

Pu2010.pdf

Access type

openaccess

Size

254 KB

Format

Adobe PDF

Checksum (MD5)

9c964cd317c737065dab714b0823291d

Loading...
Thumbnail Image
Name

p35-pu.pdf

Access type

openaccess

Size

450.88 KB

Format

Adobe PDF

Checksum (MD5)

0d96b9542921e7fbd9c0cd3992902302

Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés