Cluster Analysis and Statistical Modeling: A Unified Approach for Packet Inspection
Sheikh Muhammad Farjad, Asad Arfeen · 2020
A secure network layer capable of distinguishing between malicious and genuine traffic flows is the need of every transit service provider, edge network, corporate customer, and a common Internet user. With the emergence of advanced technologies, the demand for security has been drastically increased over the past decade. The analysis of network traffic is essential for various tasks like security, capacity planning, and visibility at various levels. In this paper, a novel architecture is proposed which exploits two powerful techniques for network traffic inspection, that is, cluster analysis and statistical modeling, and unifies them in a single framework. The proposed architecture leverages the clustering technique and statistical modeling for analyzing and inspecting the network traffic. Instead of selecting NetFlow records as the primary format, this research paper presents an approach that employs Packet Capture (PCAP) data format for network analysis. The clustering technique can be used for classifying benign and malicious traffic but there may arise many uncertainties caused by various dynamic factors due to emerging application mixture. Our proposed model uses statistical modeling for supplementing the results obtained from clustering. This unified approach for traffic analysis reduces the chances of the false alert generation that substantially deteriorates the security ecosystem. The proposed architecture inspects different parameters of network traffic to uncover any strong correlation for identifying malicious network traffic flows.