port2dist: Semantic Port Distances for Network Analytics - Inria - Institut national de recherche en sciences et technologies du numérique Access content directly
Conference Papers Year : 2019

port2dist: Semantic Port Distances for Network Analytics

Abstract

Traffic analysis is a predominant task to support multiple types of management operations. When shifting from manually built signatures to machine learning techniques, a problem resides in the model to represent traffic features. The most notable examples are the TCP and UDP ports, near port numbers in the numerical space is not representative of a close semantic from an operational point of view. We have thus developed a technique to learn meaningful metrics between ports from scanning strategies followed by attackers. In this demonstration, we propose the port2dist tool, allowing to get, seek and retrieve semantic dissimilarities between port numbers.
Fichier principal
Vignette du fichier
im2019.pdf (286.24 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-02345491 , version 1 (04-11-2019)

Identifiers

  • HAL Id : hal-02345491 , version 1

Cite

Laurent Evrard, Jérôme François, Jean-Noël Colin, Frédéric Beck. port2dist: Semantic Port Distances for Network Analytics. IM 2019 - The 16th IFIP/IEEE Symposium on Integrated Network and Service Management - Demo session, Apr 2019, Washington DC, United States. ⟨hal-02345491⟩
76 View
228 Download

Share

Gmail Facebook X LinkedIn More