Traffic features extraction and clustering analysis for abnormal behavior detection

Jian Zhang, Yan Tong, Tao Qin · 2016

With the increasing of the network bandwidth, users generate massive traffic data, how to extract the effective traffic features and achieve the goal of abnormal behavior detection is a hot and difficult problem in the area of network security monitoring. In this paper, several traffic features are proposed to capture the traffic characteristics, and then we employ the DBSCAN methods to realize abnormal traffic mining based on those features. We extract four traffic features to capture the traffic characteristics, including the ratio between number of source and destination IP addresses, ration between number of source port and destination port, ration between number of TCP packet and the total number of packets and that of number of small packets between the total number of package in a specific time window. Based on the feature extracted, we employ the DBSCAN method to cluster the network traffic in different clusters. Traffic packet in different clusters has different statistical characteristics, and the isolated points are employed to perform abnormal traffic detection. The implementation results based on traffic collect from our Lab show that proposed statistics features can capture traffic characteristics, and clustering method can classify the abnormal traffic packets into a special cluster.

Read the paper · More papers on PaperTik