Darknet Traffic Analysis and Classification Using Numerical AGM and Mean Shift Clustering Algorithm

被引:0
|
作者
Niranjana R. [1 ]
Kumar V.A. [2 ]
Sheen S. [1 ]
机构
[1] PSG College of Technology, Coimbatore
[2] CSIR Fourth Paradigm Institute, Bangalore
关键词
AGgregate and mode; Clustering; Darknet traffic analysis; Pattern recognition;
D O I
10.1007/s42979-019-0016-x
中图分类号
学科分类号
摘要
The cyberspace continues to evolve more complex than ever anticipated, and same is the case with security dynamics there. As our dependence on cyberspace is increasing day-by-day, regular and systematic monitoring of cyberspace security has become very essential. A darknet is one such monitoring framework for deducing malicious activities and the attack patterns in the cyberspace. Darknet traffic is the spurious traffic observed in the empty address space, i.e., a set of globally valid Internet Protocol (IP) addresses which are not assigned to any hosts or devices. In an ideal secure network system, no traffic is expected to arrive on such a darknet IP space. However, in reality, noticeable amount of traffic is observed in this space primarily due to the Internet wide malicious activities, attacks and sometimes due to the network level misconfigurations. Analyzing such traffic and finding distinct attack patterns present in them can be a potential mechanism to infer the attack trends in the real network. In this paper, the existing Basic and Extended AGgregate and Mode (AGM) data formats for darknet traffic analysis is studied and an efficient 29-tuple Numerical AGM data format suitable for analyzing the source IP address validated TCP connections (three-way handshake) is proposed to find attack patterns in this traffic using Mean Shift clustering algorithm. Analyzing the patterns detected from the clusters results in providing the traces of various attacks such as Mirai bot, SQL attack, and brute force. Analyzing the source IP validated TCP, darknet traffic is a potential technique in Cyber security to find the attack trends in the network. © 2019, Springer Nature Singapore Pte Ltd.
引用
收藏
相关论文
共 50 条
  • [1] Mean-Shift Blob Clustering and Tracking for Traffic Monitoring System
    Choi, Jae-Young
    Yang, Young-Kyu
    KOREAN JOURNAL OF REMOTE SENSING, 2008, 24 (03) : 235 - 243
  • [2] Darknet traffic analysis, and classification system based on modified stacking ensemble learning algorithms
    Almomani, Ammar
    INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2023, 23 (1) : 209 - 240
  • [3] A Darknet Traffic Analysis for IoT Malwares Using Association Rule Learning
    Hashimoto, Naoki
    Ozawa, Seiichi
    Ban, Tao
    Nakazato, Junji
    Shimamura, Jumpei
    INNS CONFERENCE ON BIG DATA AND DEEP LEARNING, 2018, 144 : 118 - 123
  • [4] Internet Traffic Classification Using Constrained Clustering
    Wang, Yu
    Xiang, Yang
    Zhang, Jun
    Zhou, Wanlei
    Wei, Guiyi
    Yang, Laurence T.
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (11) : 2932 - 2943
  • [5] Dynamics of a mean-shift-like algorithm and its applications on clustering
    Liu, Yiguang
    Li, Stan Z.
    Wu, Wei
    Huang, Ronggang
    INFORMATION PROCESSING LETTERS, 2013, 113 (1-2) : 8 - 16
  • [6] Graceful Register Clustering by Effective Mean Shift Algorithm for Power and Timing Balancing
    Chang, Ya-Chu
    Lin, Tung-Wei
    Jiang, Iris Hui-Ru
    Nam, Gi-Joon
    PROCEEDINGS OF THE 2019 INTERNATIONAL SYMPOSIUM ON PHYSICAL DESIGN (ISPD '19), 2019, : 11 - 18
  • [7] MEAN-SHIFT AND HIERARCHICAL CLUSTERING FOR TEXTURED POLARIMETRIC SAR IMAGE SEGMENTATION/CLASSIFICATION
    Beaulieu, Jean-Marie
    Touzi, Ridha
    2010 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, 2010, : 2519 - 2522
  • [8] K-Centers Mean-shift Reverse Mean-shift Clustering Algorithm over Heterogeneous Wireless Sensor Networks
    Xie, Qing Yan
    Cheng, Yizong
    2014 WIRELESS TELECOMMUNICATIONS SYMPOSIUM (WTS), 2014,
  • [9] Histological image segmentation using fast mean shift clustering method
    Wu, Geming
    Zhao, Xinyan
    Luo, Shuqian
    Shi, Hongli
    BIOMEDICAL ENGINEERING ONLINE, 2015, 14
  • [10] Histological image segmentation using fast mean shift clustering method
    Geming Wu
    Xinyan Zhao
    Shuqian Luo
    Hongli Shi
    BioMedical Engineering OnLine, 14