Darknet Traffic Analysis and Classification Using Numerical AGM and Mean Shift Clustering Algorithm

被引:0
|
作者
Niranjana R. [1 ]
Kumar V.A. [2 ]
Sheen S. [1 ]
机构
[1] PSG College of Technology, Coimbatore
[2] CSIR Fourth Paradigm Institute, Bangalore
关键词
AGgregate and mode; Clustering; Darknet traffic analysis; Pattern recognition;
D O I
10.1007/s42979-019-0016-x
中图分类号
学科分类号
摘要
The cyberspace continues to evolve more complex than ever anticipated, and same is the case with security dynamics there. As our dependence on cyberspace is increasing day-by-day, regular and systematic monitoring of cyberspace security has become very essential. A darknet is one such monitoring framework for deducing malicious activities and the attack patterns in the cyberspace. Darknet traffic is the spurious traffic observed in the empty address space, i.e., a set of globally valid Internet Protocol (IP) addresses which are not assigned to any hosts or devices. In an ideal secure network system, no traffic is expected to arrive on such a darknet IP space. However, in reality, noticeable amount of traffic is observed in this space primarily due to the Internet wide malicious activities, attacks and sometimes due to the network level misconfigurations. Analyzing such traffic and finding distinct attack patterns present in them can be a potential mechanism to infer the attack trends in the real network. In this paper, the existing Basic and Extended AGgregate and Mode (AGM) data formats for darknet traffic analysis is studied and an efficient 29-tuple Numerical AGM data format suitable for analyzing the source IP address validated TCP connections (three-way handshake) is proposed to find attack patterns in this traffic using Mean Shift clustering algorithm. Analyzing the patterns detected from the clusters results in providing the traces of various attacks such as Mirai bot, SQL attack, and brute force. Analyzing the source IP validated TCP, darknet traffic is a potential technique in Cyber security to find the attack trends in the network. © 2019, Springer Nature Singapore Pte Ltd.
引用
收藏
相关论文
共 50 条
  • [1] Hybridization of Mean Shift Clustering and Deep Packet Inspected Classification for Network Traffic Analysis
    Sathish A. P. Kumar
    A. Suresh
    S. Raj Anand
    K. Chokkanathan
    M. Vijayasarathy
    Wireless Personal Communications, 2022, 127 : 217 - 233
  • [2] Hybridization of Mean Shift Clustering and Deep Packet Inspected Classification for Network Traffic Analysis
    Kumar, Sathish A. P.
    Suresh, A.
    Anand, S. Raj
    Chokkanathan, K.
    Vijayasarathy, M.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (01) : 217 - 233
  • [3] Traffic Classification Using An Improved Clustering Algorithm
    Yang, Caihong
    Huang, Benxiong
    2008 INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS PROCEEDINGS, VOLS 1 AND 2, 2008, : 578 - 581
  • [4] Classification of Neural Action Potentials using Mean Shift Clustering
    Thanh Nguyen
    Khosravi, Abbas
    Hettiarachchi, Imali
    Creighton, Douglas
    Nahavandi, Saeid
    2014 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC), 2014, : 1247 - 1252
  • [5] Sample Clustering for Fast Classification by Using the Mean Shift Procedure
    Liang Lie-quan
    Liang Ying-hong
    PROCEEDINGS OF THE SECOND INTERNATIONAL SYMPOSIUM ON ELECTRONIC COMMERCE AND SECURITY, VOL II, 2009, : 179 - 183
  • [6] Darknet Traffic Classification using Machine Learning Techniques
    Iliadis, Lazaros Alexios
    Kaifas, Theodoros
    2021 10TH INTERNATIONAL CONFERENCE ON MODERN CIRCUITS AND SYSTEMS TECHNOLOGIES (MOCAST), 2021,
  • [7] Speaker clustering via the mean shift algorithm
    Stafylakis, Themos
    Katsouros, Vassilis
    Carayannis, George
    ODYSSEY 2010: THE SPEAKER AND LANGUAGE RECOGNITION WORKSHOP, 2010, : 186 - 193
  • [8] Darknet traffic classification and adversarial attacks using machine learning
    Rust-Nguyen, Nhien
    Sharma, Shruti
    Stamp, Mark
    COMPUTERS & SECURITY, 2023, 127
  • [9] Classification of vertebral column disorders and lumbar discs disease using attribute weighting algorithm with mean shift clustering
    Unal, Yavuz
    Polat, Kemal
    Kocer, H. Erdinc
    MEASUREMENT, 2016, 77 : 278 - 291
  • [10] Detection and classification of darknet traffic using machine learning methods
    Ugurlu, Mesut
    Dogru, Ibrahim Alper
    Arslan, Recep Sinan
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2023, 38 (03): : 1737 - 1746