Raw Network Traffic Data Preprocessing and Preparation for Automatic Analysis

Basil Alothman · 2019

Monitoring network traffic and trying to detect malicious activities are two of the high significance tasks carried out by Computer Security Incident Response Teams (CSIRTs). CSIRTs usually use tools to monitor and collect network traffic data, analyse the data and perform the necessary procedures if a dangerous activity is detected. However, this captured network traffic data is in raw format and must be transformed into a format that data analysis tools and platforms can process. This short paper provides a detailed explanation of several steps required to make sure the data is in good shape for analysis and automatic detection of malicious traffic. The steps are explained in a tutorial like manner and demonstrated by being executed to analyse a publicly available network traffic dataset that contains safe and malicious data. The steps and analysis illustrate that the procedure helps in making tasks such as automatic classification and clustering easy.

Read the paper · More papers on PaperTik