On detecting unidentified network traffic using pattern-based random walk

Mehran Alidoost Nia, Reza Ebrahimi Atani, Benjamin Fabian, Eduard Babulak · Security and Communication Networks · 2016

This paper presents a new approach to network traffic control based on the pattern theorem. In order to generate unique detection patterns for the process of traffic analysis, a self-avoiding walk algorithm is used. During data processing and analysis, the traffic patterns are adapted dynamically in real-time. The modified traffic patterns are systematically analyzed using a threat database. In this work, a threshold is set to distinguish and trigger critical levels of threats. The matching process is terminated under each of the three conditions: i pattern matching rate is up to 80%; ii pattern matching rates of at least five various threats are up to 50%; and iii pattern matching is enhanced up to 50% for each matched pattern using an implicit combination of threat coefficients. Our experimental results show that in the worst-case scenario, the true detection rate of malicious traffic is higher than 69%, and in the best situation, it would be about 95% for the same malicious traffic. Also, the precision of false detection for trusted patterns is negligible. Copyright © 2016 John Wiley & Sons, Ltd.

Read the paper · More papers on PaperTik