A Method for Detection and Classification of Normal Server Activities and Attacks Composed of Similar Connection Patterns

Beom-Hwan Chang · Information Security and Cryptology · 2012

ABSTRACT Security visualization is a form of the data visualization techniques in the field of network security by using security-relat ed events so that it is quickly and easily to understand network t raffic flow and security situation. In particular, the security visualization that detects the abnormal situation of network vi sualizing connections between two endpoints is a novel approach to detect unknown attack patterns and to reduce monitoring over head in packets monitoring technique. However, the session-based visualization doesn't notice a difference between normal traffic and attacks that they are composed of similar connection pattern. Therefore, in this paper, we propose an eff icient session-based visualization method for analyzing and detecting between normal server activities and attacks by using the IP address splitting and port attributes analysis. The proposed method can actually be used to detect and analyze the network security with the existing security tools because there is no dependence on other security monitoring methods. And also , it is helpful for network administrator to rapidly analyze th e security status of managed network.Keywords: Network Security, Security Visualization, Network Attack Detection 접수일(2012년 1월 12일), 수정일(2012년 10월 8일), 게재확정일(2012년 10월 16일)* 이 논문은 2012년 호원대학교 연구비 지원을 받은 것임.† 주저자, [email protected]‡ 교신저자, [email protected]

Read the paper · More papers on PaperTik