Enhancing Network Security Through Granular Computing: A Clustering-by-Time Approach to NetFlow Traffic Analysis

被引:0
|
作者
Komisarek, Mikolaj [1 ]
Pawlicki, Marek [1 ,2 ]
D'Antonio, Salvatore [3 ]
Kozik, Rafal [1 ,2 ]
Pawlicka, Aleksandra [1 ,4 ]
Choras, Michal [1 ,2 ]
机构
[1] ITTI Sp Zoo, Poznan, Poland
[2] Bydgoszcz Univ Sci & Technol, Bydgoszcz, Poland
[3] Naples Univ Parthenope, Naples, Italy
[4] Univ Warsaw, Warsaw, Poland
关键词
feature engineering; granular computing; NetFlow; network intrusion detection;
D O I
10.1145/3664476.3670882
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents a study of the effect of the size of the time window from which network features are derived on the predictive ability of a Random Forest classifier implemented as a network intrusion detection component. The network data is processed using granular computing principles, gradually increasing the time windows to allow the detection algorithm to find patterns in the data at different levels of granularity. Experiments were conducted iteratively with time windows ranging in size from 2 to 1024 seconds. Each iteration involved time-based clustering of the data, followed by splitting into training and test sets at a ratio of 67% - 33%. The Random Forest algorithm was applied as part of a 10-fold cross-validation. Assessments included standard detection metrics: accuracy, precision, F1 score, BCC, MCC and recall. The results show a statistically significant improvement in the detection of cyber attacks in network traffic with a larger time window size (p-value 0.001953125). These results highlight the effectiveness of using longer time intervals in network data analysis, resulting in increased anomaly detection.
引用
收藏
页数:8
相关论文
共 47 条
  • [1] Enhancing Network Visibility and Security through Tensor Analysis
    Baskaran, Muthu M.
    Henretty, Thomas
    Ezick, James
    Lethin, Richard
    Bruns-Smith, David
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 96 : 207 - 215
  • [2] Bayesian analysis of time series using granular computing approach
    Hryniewicz, Olgierd
    Kaczmarek, Katarzyna
    APPLIED SOFT COMPUTING, 2016, 47 : 644 - 652
  • [3] Improving Network Security through Traffic Log Anomaly Detection Using Time Series Analysis
    Rodriguez, Aitor Corchero
    de los Mozos, Mario Reyes
    COMPUTATIONAL INTELLIGENCE IN SECURITY FOR INFORMATION SYSTEMS 2010, 2010, 85 : 125 - 133
  • [4] Real-time Analysis of NetFlow Data for Generating Network Traffic Statistics using Apache Spark
    Cermak, Milan
    Jirsik, Tomas
    Lastovicka, Martin
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 1019 - 1020
  • [5] Enhancing Cloud Network Security with Innovative Time Series Analysis
    Al-Mazrawe, Amer
    Al-Musawi, Bahaa
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2025, 16 (01)
  • [6] Analysis of Encrypted Network Traffic for Enhancing Cyber-security in Dynamic Environments
    Alserhani, Faeiz
    APPLIED ARTIFICIAL INTELLIGENCE, 2024, 38 (01)
  • [7] TIFAflow: Enhancing Traffic Archiving System with Flow Granularity for Forensic Analysis in Network Security
    Chen, Zhen
    Ruan, Lingyun
    Cao, Junwei
    Yu, Yifan
    Jiang, Xin
    TSINGHUA SCIENCE AND TECHNOLOGY, 2013, 18 (04) : 406 - 417
  • [8] TIFAflow: Enhancing Traffic Archiving System with Flow Granularity for Forensic Analysis in Network Security
    Zhen Chen
    Linyun Ruan
    Junwei Cao
    Yifan Yu
    Xin Jiang
    Tsinghua Science and Technology, 2013, 18 (04) : 406 - 417
  • [9] A Software Approach to Improving Cloud Computing Datacenter Energy Efficiency and Enhancing Security through Botnet Detection
    Dinita, Razvan-Ioan
    Winckles, Adrian
    Wilson, George
    2016 IEEE 14TH INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2016, : 816 - 819
  • [10] ENHANCING INDUSTRIAL CONTROL NETWORK SECURITY THROUGH VULNERABILITY DETECTION AND ATTACK GRAPH ANALYSIS
    Liao, Yan
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2024, 25 (01): : 65 - 74