A Software Deep Packet Inspection System for Network Traffic Analysis and Anomaly Detection

被引:33
|
作者
Song, Wenguang [1 ]
Beshley, Mykola [2 ]
Przystupa, Krzysztof [3 ]
Beshley, Halyna [2 ]
Kochan, Orest [2 ,3 ]
Pryslupskyi, Andrii [2 ]
Pieniak, Daniel [4 ]
Su, Jun [5 ]
机构
[1] Yangtze Univ, Sch Comp Sci, Jingzhou 434023, Peoples R China
[2] Lviv Polytech Natl Univ, Dept Telecommun, Bandery 12, UA-79013 Lvov, Ukraine
[3] Lublin Univ Technol, Dept Automat, Nadbystrzycka 36, PL-20618 Lublin, Poland
[4] Univ Econ & Innovat Lublin, Dept Mech & Machine Bldg, Projektowa 4, PL-20209 Lublin, Poland
[5] Hubei Univ Technol, Sch Comp Sci, Wuhan 430068, Peoples R China
关键词
IoT; WSN; network anomaly; Hurst parameter; DPI; intrusion detection;
D O I
10.3390/s20061637
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
In this paper, to solve the problem of detecting network anomalies, a method of forming a set of informative features formalizing the normal and anomalous behavior of the system on the basis of evaluating the Hurst (H) parameter of the network traffic has been proposed. Criteria to detect and prevent various types of network anomalies using the Three Sigma Rule and Hurst parameter have been defined. A rescaled range (RS) method to evaluate the Hurst parameter has been chosen. The practical value of the proposed method is conditioned by a set of the following factors: low time spent on calculations, short time required for monitoring, the possibility of self-training, as well as the possibility of observing a wide range of traffic types. For new DPI (Deep Packet Inspection) system implementation, algorithms for analyzing and captured traffic with protocol detection and determining statistical load parameters have been developed. In addition, algorithms that are responsible for flow regulation to ensure the QoS (Quality of Services) based on the conducted static analysis of flows and the proposed method of detection of anomalies using the parameter Hurst have been developed. We compared the proposed software DPI system with the existing SolarWinds Deep Packet Inspection for the possibility of network traffic anomaly detection and prevention. The created software components of the proposed DPI system increase the efficiency of using standard intrusion detection and prevention systems by identifying and taking into account new non-standard factors and dependencies. The use of the developed system in the IoT communication infrastructure will increase the level of information security and significantly reduce the risks of its loss.
引用
收藏
页数:41
相关论文
共 50 条
  • [1] Development of Deep Packet Inspection System for Network Traffic Analysis and Intrusion Detection
    Cheng, Zhihui
    Beshley, Mykola
    Beshley, Halyna
    Kochan, Orest
    Urikova, Oksana
    [J]. 15TH INTERNATIONAL CONFERENCE ON ADVANCED TRENDS IN RADIOELECTRONICS, TELECOMMUNICATIONS AND COMPUTER ENGINEERING (TCSET - 2020), 2020, : 877 - 881
  • [2] An Integrative System for Deep Packet Inspection and Network Anomaly Detection & Defense
    Zhu Hongliang
    Tian Bin
    Wang Fei
    Xin Yang
    Yang Yixian
    [J]. 2011 7TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING (WICOM), 2011,
  • [3] Anomaly detection of network traffic based on wavelet packet
    Gao, Jun
    Hu, Guangmin
    Yao, Xingmiao
    Chang, Rocky K. C.
    [J]. 2006 ASIA-PACIFIC CONFERENCE ON COMMUNICATION, VOLS 1 AND 2, 2006, : 660 - 664
  • [4] Traffic scheduling for deep packet inspection in software-defined networks
    Huang, Huawei
    Li, Peng
    Guo, Song
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2017, 29 (16):
  • [5] Using Deep Packet Inspection in Cyber Traffic Analysis
    Deri, Luca
    Fusco, Francesco
    [J]. PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 89 - 94
  • [6] Cybersecurity and Network Forensics: Analysis of Malicious Traffic towards a Honeynet with Deep Packet Inspection
    Pimenta Rodrigues, Gabriel Arquelau
    Albuquerque, Robson de Oliveira
    Gomes de Deus, Flavio Elias
    de Sousa, Rafael Timoteo, Jr.
    de Oliveira Junior, Gildasio Antonio
    Garcia Villalba, Luis Javier
    Kim, Tai-Hoon
    [J]. APPLIED SCIENCES-BASEL, 2017, 7 (10):
  • [7] Automated Anomaly Detection in Virtualized Services Using Deep Packet Inspection
    Wallschlaeger, Marcel
    Gulenko, Anton
    Schmidt, Florian
    Kao, Odej
    Liu, Feng
    [J]. 14TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2017) / 12TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC 2017) / AFFILIATED WORKSHOPS, 2017, 110 : 510 - 515
  • [8] Network Traffic Anomaly Detection Using Shallow Packet Inspection and Parallel K-means Data Clustering
    Velea, Radu
    Ciobanip, Casian
    Margarit, Laurentiu
    Bica, Ion
    [J]. STUDIES IN INFORMATICS AND CONTROL, 2017, 26 (04): : 387 - 395
  • [9] Understanding the Network Traffic Constraints for Deep Packet Inspection by Passive Measurement
    Liu, Jun
    Zheng, Chao
    Guo, Li
    Liu, Xueli
    Lu, Qiuwen
    [J]. 2018 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS ENGINEERING (ICISE), 2018, : 26 - 32
  • [10] Towards the Detection of Encrypted BitTorrent Traffic through Deep Packet Inspection
    Carvalho, David A.
    Pereira, Manuela
    Freire, Mario M.
    [J]. SECURITY TECHNOLOGY, PROCEEDINGS, 2009, 58 : 265 - 272