Visual Analytics for Anomaly Classification in LAN Based on Deep Convolutional Neural Network

Yuwei Sun, Hiroshi Esaki, Hideya Ochiai · 2020

Information systems accelerate the advancement of society. However, malicious manipulation of information would bring great harm. Recently, criminal groups are increasingly involved in cybercrime, especially in the Local Area Network (LAN). Several methods are being used to analyze network traffic in LAN such as extracting the transition patterns in traffic flows, however, research on visualization of network traffic, thus detecting and classifying various abnormal events, is insufficient. In this research, we propose visual analytics for generating feature maps of network events based on protocol information. We extract protocol information of ARP, TCP, and UDP from network traffic and generate each type of feature maps. Then for each event, we merge these three types into one image by putting them into different channels, to represent features. We simulate and visualize eight types of network events in LAN which are the normal, arp scan, tcp scan, scan of tcp port 23, scan of tcp port 80, udp scan, scan of udp port 137 and scan of udp port 1900. Then for this multiclass classification problem, we adopt a deep convolutional neural network (CNN) to differentiate between these network events, with these eight types as labels and generated feature maps as inputs. We evaluated the scheme using precision, recall, and F-measure in two LANs, at last, achieving an average F-measure of 0.76.

Read the paper · More papers on PaperTik