Stability Visualizations as a Low-complexity Descriptor of Network Host Behaviour
Matt MacDonald, Carrie E. Gates, Teryl Taylor, Diana Paterson, Stephen Brooks · Procedia Computer Science · 2013
Detecting anomalous or malicious behaviour from NetFlow data alone is a difficult task due mainly to the limited information available in a NetFlow record. In this paper we propose a “stability” metric based on only four elements of the NetFlow record (source address, destination address, port, time), which may be efficiently visualized. We show that despite not having access to packet payloads, visualizations of this stability metric display clear patterns in the case of certain anomalous network events. (scanning behaviour, peer-to-peer behaviour, etc.) We propose that these visualizations may be useful to the network analyst in detecting malicious behaviour or other deviations from typical network behaviour.