A Parallel Approach to PCA Based Malicious Activity Detection in Distributed Honeypot Data

Bernardo David, João Paulo C. L. da Costa, Anderson C. A. Nascimento, Marcelo Holtz, Dino Amaral, Rafael Sousa Júnior · The International Journal of Forensic Computer Science · 2011

Abstract- Model order selection (MOS) schemes, which are frequently employed in several signal processing applications, are shown to be effective tools for the detection of malicious activities in honeypot data. In this paper, we extend previous results by proposing an efficient and parallel MOS method for blind automatic malicious activity detection in distributed honeypots. Our proposed scheme does not require any previous information on attacks or human intervention. We model network traffic data as signals and noise and then apply modified signal processing methods. However, differently from the previous centralized solutions, we propose that the data colected by each honeypot node be processed by nodes in a cluster (that may consist of the collection nodes themselves) and then grouped to obtain the final results. This is achieved by having each node locally compute the Eigenvalue Decomposition (EVD) to its own sample correlation matrix (obtained from the honeypot data) and transmit the resulting eigenvalues to a central node, where the global eigenvalues and final model order are computed. The model order computed from the global eigenvalues through RADOI represents the number of malicious activities detected in the analysed data. The feasibility of the proposed approach is demonstrated through simulation experiments. (6)

Read the paper · More papers on PaperTik