Visualization of flow data based on clustering technique for identifying network anomalies
Mayank Pal Singh, Subramanian N. Rajamenakshi · 2009
In this paper we present an approach for visualizing net flow data through clustering to identify anomalies in network traffic. Various clustering techniques are applicable for Intrusion Detection for identifying anomalous events. In this paper we present an approach based on Simple K-Means for analyzing network flow data using any flow data attribute, such as IP address, port, protocols etc, to detect anomalies. Our approach is unique and efficient due to the preprocessing and filtering techniques devised. The outcome of our approach is firstly in its capability to detect anomalous network events, secondly in providing an overview about given data set based on key network parameters and thirdly, in providing visualization of interesting security events in a very intuitive way. We present our analysis and results where we demonstrate the visualization capabilities of our approach for detecting anomalous events.