Topological Analysis and Visualisation of Network Monitoring Data: Darknet case study

Abstract : Network monitoring is a primordial source of data in cyber-security since it may reveal abnormal behaviors of users or applications. Indeed, security analysts and tools like IDS (Intrusion Detection system) or SIEM (security information and event management) rely on them as a single source of information or combined with others. In this paper, we propose a visualisation method derived from the Mapper algorithm that has been developed in the field of Topological Data Analysis (TDA). The developed method and its associated tool are able to analyze a large number of IP packets in order to make malicious activities patterns easily observable by security analysts. We applied our method to darknet data, \textit{i.e.} from an entire and supposed not used subnetwork in Internet and we have found that those observable patterns have been missed by Suricata, a widely used State-of-the-Art IDS.
Type de document :
Communication dans un congrès
8th IEEE International Workshop on Information Forensics and Security - WIFS 2016, Dec 2016, Abu Dhabi, United Arab Emirates. IEEE, 2016, Information Forensics and Security
Liste complète des métadonnées

Littérature citée [20 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01403950
Contributeur : Jérôme François <>
Soumis le : lundi 28 novembre 2016 - 10:56:15
Dernière modification le : mardi 18 décembre 2018 - 16:26:02
Document(s) archivé(s) le : lundi 20 mars 2017 - 20:33:30

Fichier

wifs16.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

  • HAL Id : hal-01403950, version 1

Collections

Citation

Marc Coudriau, Abdelkader Lahmadi, Jerome Francois. Topological Analysis and Visualisation of Network Monitoring Data: Darknet case study. 8th IEEE International Workshop on Information Forensics and Security - WIFS 2016, Dec 2016, Abu Dhabi, United Arab Emirates. IEEE, 2016, Information Forensics and Security. 〈hal-01403950〉

Partager

Métriques

Consultations de la notice

880

Téléchargements de fichiers

760