Network Attack Detection Based on Peer-to-Peer Clustering of SNMP Data

被引:0
|
作者
Cerroni, Walter [1 ]
Monti, Gabriele [1 ]
Moro, Gianluca [1 ]
Ramilli, Marco [1 ]
机构
[1] DEIS Univ Bologna, I-47521 Cesena, FC, Italy
关键词
Network security; distributed intrusion detection; SNMP; data mining; data clustering; peer-to-peer; ANOMALY DETECTION;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Network intrusion detection is a key security issue that can be tackled by means of different approaches. This paper describes a novel methodology for network attack detection based on the use of data mining techniques to process traffic information collected by a monitoring station from a set of hosts using the Simple Network Management Protocol (SNMP). The proposed approach, adopting unsupervised clustering techniques, allows to effectively distinguish normal traffic behavior from malicious network activity and to determine with very good accuracy what kind of attack is being perpetrated. Several monitoring stations are then interconnected according to any peer-to-peer network in order to share the knowledge base acquired with the proposed methodology, thus increasing the detection capabilities. An experimental test-bed has been implemented, which reproduces the case of a real web server under several attack techniques. Results of the experiments show the effectiveness of the proposed solution, with no detection failures of true attacks and very low false-positive rates (i.e. false alarms).
引用
收藏
页码:417 / 430
页数:14
相关论文
共 50 条
  • [41] Peer-to-peer determination of proximity using wireless network data
    Meunier, JL
    SECOND IEEE ANNUAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS, PROCEEDINGS, 2004, : 70 - 74
  • [42] Latency-Adaptive Positioning of Nano Data Centers for Peer-to-Peer Communication based on Clustering
    Maiti, Ananda
    Kist, Alexander A.
    Maxwell, Andrew
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION WORKSHOP (ICCW), 2015, : 1921 - 1927
  • [43] Peer-To-Peer traffic detection based on periodic sampling
    Yu, FuXing
    Suo, YiNa
    Song, DingLi
    2010 2ND INTERNATIONAL WORKSHOP ON DATABASE TECHNOLOGY AND APPLICATIONS PROCEEDINGS (DBTA), 2010,
  • [44] Global state detection based on peer-to-peer interactions
    Chandra, P
    Kshemkalyani, AD
    EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005, 2005, 3824 : 560 - 571
  • [45] Peer-to-Peer Based Intrusion Detection Modeling and Analysis
    Zhang Xiaosong
    Chen Ting
    Ma Yue
    Li Hua
    2009 FIRST INTERNATIONAL CONFERENCE ON FUTURE INFORMATION NETWORKS, 2009, : 213 - +
  • [46] Global state detection based on peer-to-peer interactions
    Chandra, P. (pchandra@cs.uic.edu), (Springer Verlag):
  • [47] Approximate Distributed K-Means Clustering over a Peer-to-Peer Network
    Datta, Souptik
    Giannella, Chris R.
    Kargupta, Hillol
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2009, 21 (10) : 1372 - 1388
  • [48] Clustering in peer-to-peer file sharing workloads
    Le Fessant, F
    Handurukande, S
    Kermarrec, AM
    Massoulié, L
    PEER-TO-PEER SYSTEMS III, 2004, 3279 : 217 - 226
  • [49] Improved clustering algorithm in Peer-to-Peer environments
    Tian, Ye
    Liu, Da-You
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2010, 40 (06): : 1639 - 1643
  • [50] TOWARDS A SECURE DATA SHARING PEER-TO-PEER NETWORK BASED ON GEOMETRIC AND SEMANTIC DISTANCES
    Sambotin, Ana-Delia
    Andreica, Mugurel Ionut
    EUROMEDIA 2012: 17TH ANNUAL SCIENTIFIC CONFERENCE ON WEB TECHNOLOGY, NEW MEDIA COMMUNICATIONS AND TELEMATICS THEORY METHODS, TOOLS AND APPLICATIONS, 2012, : 93 - 99