Structure-based Data Mining and Screening for Network Traffic Data

Hisashi Tsuruta, Takayoshi Shoudai · 2013

Darknet monitoring plays an important role for understanding various botnet activities for early detection of the threats on the Internet caused by the botnets. However, common illegal accesses by ordinary malware make such detection difficult. To remove such accesses by ordinary malware from the results of network monitoring, Tsuruta et al. (2012) proposed an automatic data screening method by discovering frequent string-based patterns appearing in observed network traffic data. In this paper, we propose a data mining and screening method based on 2-edge-connected bipartite graph structures. We applied our method to network traffic data observed in the darknet and report the results.

Read the paper · More papers on PaperTik