NetFlow Anomaly Detection Though Parallel Cluster Density Analysis in Continuous Time-Series - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

NetFlow Anomaly Detection Though Parallel Cluster Density Analysis in Continuous Time-Series

Enda Fallon
  • Fonction : Auteur
  • PersonId : 1015918
Paul Connolly
  • Fonction : Auteur
  • PersonId : 1025830
Abir Awad
  • Fonction : Auteur
  • PersonId : 1025831

Résumé

The increase in malicious network based attacks has resulted in a growing interest in network anomaly detection. The ability to detect unauthorized or malicious activity on a network is of importance to any organization. With the increase in novel attacks, anomaly detection techniques can be more successful in detecting unknown malicious activity in comparison to traditional signature based methods. However, in a real-world environment, there are many variables that cannot be simulated. This paper proposes an architecture where parallel clustering algorithms work concurrently in order to detect abnormalities that may be lost while traversing over time-series windows. The presented results describe the NetFlow activity of the NPD Group, Inc. over a 24-hour period. The presented results contain real-world anomalies that were detected.
Fichier principal
Vignette du fichier
453598_1_En_18_Chapter.pdf (1.29 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01675428 , version 1 (04-01-2018)

Licence

Paternité

Identifiants

Citer

Kieran Flanagan, Enda Fallon, Paul Connolly, Abir Awad. NetFlow Anomaly Detection Though Parallel Cluster Density Analysis in Continuous Time-Series. 15th International Conference on Wired/Wireless Internet Communication (WWIC), Jun 2017, St. Petersburg, Russia. pp.221-232, ⟨10.1007/978-3-319-61382-6_18⟩. ⟨hal-01675428⟩
142 Consultations
129 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More