Unsupervised host behavior classification from connection patterns

Abstract : A novel host behavior classification approach is proposed as a preliminary step toward traffic classification and anomaly detection in network communication. Though many attempts described in the literature were devoted to flow or application classifications, these approaches are not always adaptable to operational constraints of traffic monitoring (expected to work even without packet payload, without bidirectionality, on highspeed networks or from flow reports only...). Instead, the classification proposed here relies on the leading idea that traffic is relevantly analyzed in terms of host typical behaviors: typical connection patterns of both legitimate applications (data sharing, downloading,...) and anomalous (eventually aggressive) behaviors are obtained by profiling traffic at the host level using unsupervised statistical classification. Classification at the host level is not reducible to flow or application classification, and neither is the contrary: they are different operations which might have complementary roles in network management. The proposed host classification is based on a nine-dimensional feature space evaluating host Internet connectivity, dispersion and exchanged traffic content. A Minimum Spanning Tree (MST) clustering technique is developed that does not require any supervised learning step to produce a set of statistically established typical host behaviors. Not relying on a priori defined classes of known behaviors enables the procedure to discover new host behaviors, that potentially were never observed before. This procedure is applied to traffic collected over the entire year 2008 on a transpacific (Japan/USA) link. A cross-validation of this unsupervised classification against a classical port-based inspection and a state-of-the-art method provides assessment of the meaningfulness and the relevance of the obtained classes for host behaviors.
Complete list of metadatas

Cited literature [34 references]  Display  Hide  Download

https://hal-ens-lyon.archives-ouvertes.fr/ensl-00488248
Contributor : Pierre Borgnat <>
Submitted on : Wednesday, June 9, 2010 - 9:47:07 AM
Last modification on : Thursday, February 7, 2019 - 5:57:41 PM
Long-term archiving on : Thursday, December 1, 2016 - 7:07:00 AM

File

ijnm_rev2_bis.pdf
Files produced by the author(s)

Identifiers

  • HAL Id : ensl-00488248, version 2

Citation

Guillaume Dewaele, Yosuke Himura, Pierre Borgnat, Kensuke Fukuda, Patrice Abry, et al.. Unsupervised host behavior classification from connection patterns. International Journal of Network Management, Wiley, 2010, 20 (5), pp.317-337. ⟨ensl-00488248v2⟩

Share

Metrics

Record views

528

Files downloads

319