Darknet Traffic Analysis and Classification Using Numerical AGM and Mean Shift Clustering Algorithm

被引:0
|
作者
Niranjana R. [1 ]
Kumar V.A. [2 ]
Sheen S. [1 ]
机构
[1] PSG College of Technology, Coimbatore
[2] CSIR Fourth Paradigm Institute, Bangalore
关键词
AGgregate and mode; Clustering; Darknet traffic analysis; Pattern recognition;
D O I
10.1007/s42979-019-0016-x
中图分类号
学科分类号
摘要
The cyberspace continues to evolve more complex than ever anticipated, and same is the case with security dynamics there. As our dependence on cyberspace is increasing day-by-day, regular and systematic monitoring of cyberspace security has become very essential. A darknet is one such monitoring framework for deducing malicious activities and the attack patterns in the cyberspace. Darknet traffic is the spurious traffic observed in the empty address space, i.e., a set of globally valid Internet Protocol (IP) addresses which are not assigned to any hosts or devices. In an ideal secure network system, no traffic is expected to arrive on such a darknet IP space. However, in reality, noticeable amount of traffic is observed in this space primarily due to the Internet wide malicious activities, attacks and sometimes due to the network level misconfigurations. Analyzing such traffic and finding distinct attack patterns present in them can be a potential mechanism to infer the attack trends in the real network. In this paper, the existing Basic and Extended AGgregate and Mode (AGM) data formats for darknet traffic analysis is studied and an efficient 29-tuple Numerical AGM data format suitable for analyzing the source IP address validated TCP connections (three-way handshake) is proposed to find attack patterns in this traffic using Mean Shift clustering algorithm. Analyzing the patterns detected from the clusters results in providing the traces of various attacks such as Mirai bot, SQL attack, and brute force. Analyzing the source IP validated TCP, darknet traffic is a potential technique in Cyber security to find the attack trends in the network. © 2019, Springer Nature Singapore Pte Ltd.
引用
收藏
相关论文
共 50 条
  • [31] Image segmentation using mean shift based clustering
    Li, Yinqling
    Bo, Shukui
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE INFORMATION COMPUTING AND AUTOMATION, VOLS 1-3, 2008, : 1322 - 1325
  • [32] Internet Traffic Classification Using Constrained Clustering
    Wang, Yu
    Xiang, Yang
    Zhang, Jun
    Zhou, Wanlei
    Wei, Guiyi
    Yang, Laurence T.
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (11) : 2932 - 2943
  • [33] Improving the Mean Shift Clustering Algorithm for Universal Background Model (UBM)
    R. Suneetha Rani
    P. Madhavan
    A. Prakash
    Circuits, Systems, and Signal Processing, 2022, 41 : 3882 - 3902
  • [34] Dynamics of a mean-shift-like algorithm and its applications on clustering
    Liu, Yiguang
    Li, Stan Z.
    Wu, Wei
    Huang, Ronggang
    INFORMATION PROCESSING LETTERS, 2013, 113 (1-2) : 8 - 16
  • [35] Robust Truth Discovery Scheme Based on Mean Shift Clustering Algorithm
    Chen, Jingxue
    Yang, Jingkang
    Huang, Juan
    Liu, Yining
    JOURNAL OF INTERNET TECHNOLOGY, 2021, 22 (04): : 835 - 842
  • [36] Improving the Mean Shift Clustering Algorithm for Universal Background Model (UBM)
    Rani, R. Suneetha
    Madhavan, P.
    Prakash, A.
    CIRCUITS SYSTEMS AND SIGNAL PROCESSING, 2022, 41 (07) : 3882 - 3902
  • [37] Methodology of Mean Shift Clustering Algorithm Implementation Based on Dataflow Computer
    Salibekyan, Sergey
    Ivanova, Elena
    Vishnekov, Andrey
    2019 XVI INTERNATIONAL SYMPOSIUM PROBLEMS OF REDUNDANCY IN INFORMATION AND CONTROL SYSTEMS (REDUNDANCY), 2019, : 177 - 180
  • [38] WEDMS: An advanced mean shift clustering algorithm for LDoS attacks detection
    Tang, Dan
    Man, Jianping
    Tang, Liu
    Feng, Ye
    Yang, Qiuwei
    AD HOC NETWORKS, 2020, 102
  • [39] Hippocampal Segmentation using Mean Shift Algorithm
    Lopez Palafox, Guadalupe Desiree
    Sosa Ortiz, Ana Luisa
    Marrufo Melendez, Oscar
    Morales Ballesteros, Orlando
    Perez Gonzalez, Jorge Luis
    Jimenez Alaniz, Juan Ramon
    12TH INTERNATIONAL SYMPOSIUM ON MEDICAL INFORMATION PROCESSING AND ANALYSIS, 2017, 10160
  • [40] Improved Harris Combined With Clustering Algorithm for Data Traffic Classification
    Liu, Qingli
    Li, Mengqian
    Cao, Na
    Zhang, Zhenya
    Yang, Guoqiang
    IEEE ACCESS, 2022, 10 : 72815 - 72824