Darknet Traffic Analysis and Classification Using Numerical AGM and Mean Shift Clustering Algorithm

被引:0
|
作者
Niranjana R. [1 ]
Kumar V.A. [2 ]
Sheen S. [1 ]
机构
[1] PSG College of Technology, Coimbatore
[2] CSIR Fourth Paradigm Institute, Bangalore
关键词
AGgregate and mode; Clustering; Darknet traffic analysis; Pattern recognition;
D O I
10.1007/s42979-019-0016-x
中图分类号
学科分类号
摘要
The cyberspace continues to evolve more complex than ever anticipated, and same is the case with security dynamics there. As our dependence on cyberspace is increasing day-by-day, regular and systematic monitoring of cyberspace security has become very essential. A darknet is one such monitoring framework for deducing malicious activities and the attack patterns in the cyberspace. Darknet traffic is the spurious traffic observed in the empty address space, i.e., a set of globally valid Internet Protocol (IP) addresses which are not assigned to any hosts or devices. In an ideal secure network system, no traffic is expected to arrive on such a darknet IP space. However, in reality, noticeable amount of traffic is observed in this space primarily due to the Internet wide malicious activities, attacks and sometimes due to the network level misconfigurations. Analyzing such traffic and finding distinct attack patterns present in them can be a potential mechanism to infer the attack trends in the real network. In this paper, the existing Basic and Extended AGgregate and Mode (AGM) data formats for darknet traffic analysis is studied and an efficient 29-tuple Numerical AGM data format suitable for analyzing the source IP address validated TCP connections (three-way handshake) is proposed to find attack patterns in this traffic using Mean Shift clustering algorithm. Analyzing the patterns detected from the clusters results in providing the traces of various attacks such as Mirai bot, SQL attack, and brute force. Analyzing the source IP validated TCP, darknet traffic is a potential technique in Cyber security to find the attack trends in the network. © 2019, Springer Nature Singapore Pte Ltd.
引用
收藏
相关论文
共 50 条
  • [21] Convergence analysis of mean shift algorithm
    School of Information Science and Engineering, Central South University, Changsha 410083, China
    不详
    Ruan Jian Xue Bao, 2007, 2 (205-212):
  • [22] A mean shift algorithm incorporating reachable distance for spatial clustering
    Peng, Youwei
    Luo, Yalan
    Zhang, Qiongbing
    Xie, Chengwang
    Information Sciences, 2025, 689
  • [23] Determining Best Text Clustering Number with Mean Shift Algorithm
    Zhao H.
    Yu L.
    Zhou Q.
    Data Analysis and Knowledge Discovery, 2019, 3 (09) : 27 - 35
  • [24] Fast Mean Shift Based Traffic Image Filtering Algorithm
    Zhang Yu
    Shi Zhong-ke
    Wang Run-quan
    2009 IEEE INTELLIGENT VEHICLES SYMPOSIUM, VOLS 1 AND 2, 2009, : 168 - 171
  • [25] Texture classification and retrieval by adaptive mean shift clustering and edge images
    Yun, Anastasiya
    Lee, Jong-Soo
    IFOST 2006: 1ST INTERNATIONAL FORUM ON STRATEGIC TECHNOLOGY, PROCEEDINGS: E-VEHICLE TECHNOLOGY, 2006, : 121 - +
  • [26] Mean shift based clustering in high dimensions: A texture classification example
    Georgescu, B
    Shimshoni, I
    Meer, P
    NINTH IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION, VOLS I AND II, PROCEEDINGS, 2003, : 456 - 463
  • [27] Darknet traffic analysis, and classification system based on modified stacking ensemble learning algorithms
    Almomani, Ammar
    INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2023,
  • [28] A Novel Approach for Color Image Segmentation Using Iterative Partitioning Mean Shift Clustering Algorithm
    Naik, P. Pedda Sadhu
    Gopal, T. Venu
    2015 INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND SIGNAL PROCESSING (ICCSP), 2015, : 1516 - 1519
  • [29] A Darknet Traffic Analysis for IoT Malwares Using Association Rule Learning
    Hashimoto, Naoki
    Ozawa, Seiichi
    Ban, Tao
    Nakazato, Junji
    Shimamura, Jumpei
    INNS CONFERENCE ON BIG DATA AND DEEP LEARNING, 2018, 144 : 118 - 123
  • [30] Analyzing Data Changes Using Mean Shift Clustering
    Sharet, Nir
    Shimshoni, Ilan
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2016, 30 (07)