Knowledge Discovery from Honeypot Data for Monitoring Malicious Attacks

被引:0
作者
Jin, Huidong [1 ,2 ]
de Vel, Olivier [3 ]
Zhang, Ke [1 ,2 ]
Liu, Nianjun [1 ,2 ]
机构
[1] NICTA Canberra Lab, Locked Bag 8001, Canberra, ACT 2601, Australia
[2] Australian Natl Univ, RSISE, Canberra, ACT 0200, Australia
[3] Def Sci & Technol Org, Command Ctrl Commun & Intelligence Div, Edinburg, SA 5111, Australia
来源
AI 2008: ADVANCES IN ARTIFICIAL INTELLIGENCE, PROCEEDINGS | 2008年 / 5360卷
基金
澳大利亚研究理事会;
关键词
Knowledge discovery; outlier detection; density-based cluster visualisation; botnet; honeypot data; Internet security;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Owing to the spread of worms and botnets, cyber attacks have significantly increased in volume, coordination and sophistication. Cheap rentable botnet services, e.g., have resulted in sophisticated botnets becoming an effective and popular tool for committing online crime these days. Honeypots, as information system traps, axe monitoring or deflecting malicious attacks on the Internet. To understand the attack patterns generated by botnets by virtue of the analysis of the data collected by honeypots, we propose an approach that integrates a clustering structure visualisation technique with outlier detection techniques. These techniques complement each other and provide end users both a big-picture view and actionable knowledge of high-dimensional data. We introduce KNOF (K-nearest Neighbours Outlier Factor) as the outlier definition technique to reach a trade-off between global and local outlier definitions, i.e., K-th-Nearest Neighbour (KNN) and Local Outlier Factor (LOF) respectively. We propose an algorithm to discover the most significant KNOF outliers. We implement these techniques in our hpdAnalyzer tool. The tool is successfully used to comprehend honeypot data. A series of experiments show that our proposed KNOF technique substantially outperforms LOF and, to a lesser degree, KNN for real-world honeypot data.
引用
收藏
页码:470 / +
页数:2
相关论文
共 50 条
  • [31] Knowledge Discovery for Scalable Data Mining
    Chhabra, Indu
    Suri, Gunmala
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2019, 6 (21) : 1 - 9
  • [32] Big Data Trend: Knowledge Discovery on the Unstructured Data
    Abu Muntalib, Shamsiah
    Sidi, Fatimah
    Jabar, Marzanah A.
    Ishak, Iskandar
    PROCEEDING OF KNOWLEDGE MANAGEMENT INTERNATIONAL CONFERENCE (KMICE) 2014, VOLS 1 AND 2, 2014, : 338 - 342
  • [33] Knowledge Discovery from Web Usage Data: Complete Preprocessing Methodology
    Raju, G. T.
    Satyanarayana, P. S.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2008, 8 (01): : 179 - 186
  • [34] Prov-Dominoes: An approach for knowledge discovery from provenance data
    Alencar, Victor
    Kohwalter, Troy
    Braganholo, Vanessa
    Da Silva Junior, Jose Ricardo
    Murta, Leonardo
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 245
  • [35] Knowledge discovery of geochemical patterns from a data-driven perspective
    Yin, Bojun
    Zuo, Renguang
    Xiong, Yihui
    Li, Yongsheng
    Yang, Weigang
    JOURNAL OF GEOCHEMICAL EXPLORATION, 2021, 231 (231)
  • [36] Detection of Good and Bad Sensor Nodes in the Presence of Malicious Attacks and Its Application to Data Aggregation
    Yessembayev, Anes
    Sarkar, Dilip
    Sikder, Faisal
    IEEE TRANSACTIONS ON SIGNAL AND INFORMATION PROCESSING OVER NETWORKS, 2018, 4 (03): : 549 - 563
  • [37] Knowledge discovery process for scientific and engineering data
    Barrios, LJ
    Rudolph, S
    DATA MINING AND KNOWLEDGE DISCOVERY: THEORY, TOOLS AND TECHNOLOGY IV, 2002, 4730 : 118 - 125
  • [38] Research on Visual Data Mining and Knowledge Discovery
    Zhang Qingwei
    RECENT ADVANCE IN STATISTICS APPLICATION AND RELATED AREAS, VOLS I AND II, 2009, : 1010 - 1013
  • [39] Poster Abstract: Topological Analysis for Knowledge Discovery from Building Sensor Data
    Gupta, Manik
    2020 ACM/IEEE FIFTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS DESIGN AND IMPLEMENTATION (IOTDI 2020), 2020, : 258 - 259
  • [40] A knowledge discovery and visualisation method for unearthing emotional states from physiological data
    Nectarios Costadopoulos
    Md Zahidul Islam
    David Tien
    International Journal of Machine Learning and Cybernetics, 2021, 12 : 843 - 858