Characterization of network behavior to detect changes
Karl Tgavalekos, Josephine Namayanja, Rasheed Alhassan · 2018
This paper explores the process of change detection to identify shifts in network behavior that are associated with cyberattacks. Our objective is to select targeted points such as key nodes whose role on the network is vital to ensure communication across the network. While traditional intrusion detection techniques require knowledge of attack signatures, they are limited in cases of novel attacks. More so the process of anomaly detection focuses on identifying the unusual behavior in the network. However, communication patterns fluctuate especially in real world networks which are complex and thus makes it challenging to conclude what is truly abnormal. Our approach is geared towards detecting change associated to potential threats such as the onset of a cyberattack, which changes the way a network appears in terms of key graph properties. This paper highlights the importance of drilling down into the network to focus on key network points in identifying potential cyber threats that may be difficult to detect on a larger scale.