Sniffing Detection Based on Network Traffic Probing and Machine Learning

被引:10
|
作者
Gregorczyk, Marcin [1 ]
Zorawski, Piotr [1 ]
Nowakowski, Piotr [1 ]
Cabaj, Krzysztof [2 ]
Mazurczyk, Wojciech [2 ]
机构
[1] Warsaw Univ Technol, Inst Telecommun, PL-00665 Warsaw, Poland
[2] Warsaw Univ Technol, Inst Comp Sci, PL-00665 Warsaw, Poland
基金
欧盟地平线“2020”;
关键词
Security; Machine learning; Protocols; Tools; Internet; Software; AI; artificial intelligence; ML; machine learning; network security; sniffing; threat detection;
D O I
10.1109/ACCESS.2020.3016076
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber attacks are on the rise and each day cyber criminals are developing more and more sophisticated methods to compromise the security of their targets. Sniffing is one of the most important techniques that enables the attacker to collect information on the vulnerabilities of the devices, protocols and applications that can be exploited within the targeted network. It relies mainly on passively analyzing the traffic exchanged within the network, and due to its nature, such an activity is difficult to discover. That is why, in this article, we first revisit existing techniques and tools that can be used to perform sniffing as well as the corresponding mitigation methods. Based on this background, we propose a novel measurement-based detection method that infers whether the sniffing software is active on the suspected machine by network traffic probing and machine learning techniques. The presented experimental results prove that the proposed solution is effective.
引用
收藏
页码:149255 / 149269
页数:15
相关论文
共 50 条
  • [31] Machine learning approaches to network intrusion detection for contemporary internet traffic
    Ilyas, Muhammad U.
    Alharbi, Soltan Abed
    COMPUTING, 2022, 104 (05) : 1061 - 1076
  • [32] Machine Learning Based Network Intrusion Detection
    Lee, Chie-Hong
    Su, Yann-Yean
    Lin, Yu-Chun
    Lee, Shie-Jue
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND APPLICATIONS (ICCIA), 2017, : 79 - 83
  • [33] Anomaly-Based Intrusion Detection by Machine Learning: A Case Study on Probing Attacks to an Institutional Network
    Tufan, Emrah
    Tezcan, Cihangir
    Acarturk, Cengiz
    IEEE ACCESS, 2021, 9 : 50078 - 50092
  • [34] Developing machine learning based framework for the network traffic prediction
    Murugesan, G.
    Jaiswal, Rachana
    Kshatri, Sapna Singh
    Bhonsle, Devanand
    INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING, 2022, 13 (03): : 777 - 784
  • [35] Study of Internet Network Traffic Identification Based on Machine Learning
    Ma, Yongli
    PROCEEDINGS OF 2008 INTERNATIONAL PRE-OLYMPIC CONGRESS ON COMPUTER SCIENCE, VOL I: COMPUTER SCIENCE AND ENGINEERING, 2008, : 207 - 212
  • [36] Flow Based Botnet Traffic Detection Using Machine Learning
    Gahelot, Parul
    Dayal, Neelam
    PROCEEDINGS OF ICETIT 2019: EMERGING TRENDS IN INFORMATION TECHNOLOGY, 2020, 605 : 418 - 426
  • [37] Real time malware detection in encrypted network traffic using machine learning with time based features
    Singh, Abhay Pratap
    Singh, Mahendra
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2023, 26 (03): : 841 - 850
  • [38] Machine learning-based early detection of IoT botnets using network-edge traffic
    Kumar, Ayush
    Shridhar, Mrinalini
    Swaminathan, Sahithya
    Lim, Teng Joon
    COMPUTERS & SECURITY, 2022, 117
  • [39] Robust genetic machine learning ensemble model for intrusion detection in network traffic
    Akhtar, Muhammad Ali
    Qadri, Syed Muhammad Owais
    Siddiqui, Maria Andleeb
    Mustafa, Syed Muhammad Nabeel
    Javaid, Saba
    Ali, Syed Abbas
    SCIENTIFIC REPORTS, 2023, 13 (01):
  • [40] Machine Learning in Cybersecurity: Advanced Detection and Classification Techniques for Network Traffic Environments
    Hassan, Samer El Hajj
    Duong-Trung, Nghia
    EAI Endorsed Transactions on Industrial Networks and Intelligent Systems, 2024, 11 (03)