Unsupervised host behavior classification from connection patterns - ENS de Lyon - École normale supérieure de Lyon Accéder directement au contenu
Article Dans Une Revue International Journal of Network Management Année : 2010

Unsupervised host behavior classification from connection patterns

Guillaume Dewaele
  • Fonction : Auteur
  • PersonId : 842999
Yosuke Himura
  • Fonction : Auteur
  • PersonId : 871665
Kensuke Fukuda
  • Fonction : Auteur
  • PersonId : 843234
Patrice Abry
Kenjiro Cho
  • Fonction : Auteur
  • PersonId : 843235
Hiroshi Esaki
  • Fonction : Auteur
  • PersonId : 871666

Résumé

A novel host behavior classification approach is proposed as a preliminary step toward traffic classification and anomaly detection in network communication. Though many attempts described in the literature were devoted to flow or application classifications, these approaches are not always adaptable to operational constraints of traffic monitoring (expected to work even without packet payload, without bidirectionality, on highspeed networks or from flow reports only...). Instead, the classification proposed here relies on the leading idea that traffic is relevantly analyzed in terms of host typical behaviors: typical connection patterns of both legitimate applications (data sharing, downloading,...) and anomalous (eventually aggressive) behaviors are obtained by profiling traffic at the host level using unsupervised statistical classification. Classification at the host level is not reducible to flow or application classification, and neither is the contrary: they are different operations which might have complementary roles in network management. The proposed host classification is based on a nine-dimensional feature space evaluating host Internet connectivity, dispersion and exchanged traffic content. A Minimum Spanning Tree (MST) clustering technique is developed that does not require any supervised learning step to produce a set of statistically established typical host behaviors. Not relying on a priori defined classes of known behaviors enables the procedure to discover new host behaviors, that potentially were never observed before. This procedure is applied to traffic collected over the entire year 2008 on a transpacific (Japan/USA) link. A cross-validation of this unsupervised classification against a classical port-based inspection and a state-of-the-art method provides assessment of the meaningfulness and the relevance of the obtained classes for host behaviors.
Fichier principal
Vignette du fichier
ijnm_rev2.pdf (343.3 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

ensl-00488248 , version 1 (01-06-2010)
ensl-00488248 , version 2 (09-06-2010)

Identifiants

  • HAL Id : ensl-00488248 , version 1

Citer

Guillaume Dewaele, Yosuke Himura, Pierre Borgnat, Kensuke Fukuda, Patrice Abry, et al.. Unsupervised host behavior classification from connection patterns. International Journal of Network Management, 2010, 20. ⟨ensl-00488248v1⟩
421 Consultations
499 Téléchargements

Partager

Gmail Facebook X LinkedIn More