Device-Type Profiling for Network Access Control Systems using Clustering-Based Multivariate Gaussian Outlier Score

Musa Abubakar Muhammad, Uchenna Ani, Aminu Aliyu Abdullahi, Petar Radanliev · The 5th International Conference on Future Networks & Distributed Systems · 2021

Behaviour profiling is used in organisations to identify the working patterns of agents: humans or devices. It can be used to detect abnormal patterns of devices in an organisation’s BYOD network to help control network access. Although BYOD offers great benefits of improving productivity and job satisfaction while reducing cost, it bears some security issues around access control with limitations in addressing insider threat scenarios. This means that motivated and determined attackers with valid access credentials can exploit the weaknesses to compromise the system. The limitation of mobile devices can mean that traditional network access control mechanism are ineffective in addressing insider threats, and can impact on device capacity and functionality. Thus, it is crucial to explore other ways of identifying insider threats from anomalous device behaviours. We propose a device-type profiling for threat detection which uses packet inter-arrival time patterns of devices for automatic identification of abnormal device-types. Experimental tests using clustering-based multivariate gaussian outlier score (CMGOS) to clearly distinguish and label normal and abnormal inter-arrival time patterns yielded promising results. This affirms the effectiveness of the proposed approach to support system administrators in monitoring and detecting insider threats for timely and effective access control response.

Read the paper · More papers on PaperTik