Structure-based Data Mining and Screening for Network Traffic Data
Hisashi Tsuruta, Takayoshi Shoudai · 2013
Darknet monitoring plays an important role for understanding various botnet activities for early detection of the threats on the Internet caused by the botnets. However, common illegal accesses by ordinary malware make such detection difficult. To remove such accesses by ordinary malware from the results of network monitoring, Tsuruta et al. (2012) proposed an automatic data screening method by discovering frequent string-based patterns appearing in observed network traffic data. In this paper, we propose a data mining and screening method based on 2-edge-connected bipartite graph structures. We applied our method to network traffic data observed in the darknet and report the results.