Big Data Testbed for Network Attack Detection

Acta Polytechnica Hungarica · 2016

Establishing an effective defense strategy in IT security is essential on one hand, but very challenging on the other hand.According to the 2014 Cyberthreat Defence Report [1] that involved more than 750 security decision makers and practitioners, more than 60% of organizations had been breached in 2013.Big data analytics in security provides the possibility to gather and analyse massive amounts of digital information in order to predict and prevent these attacks.However, since collecting the needed data in an efficient, complete and reliable fashion encounters problems, the industry is lacking and could truly benefit from a tool offering benchmark data, provided in a platform, which would allow gauging and improving the effectiveness of security defence algorithms.To this end in this paper we introduce a platform that allows one to generate large parametrized datasets of simulated Internet traffic consisting of the combination of attack-free and malicious network traffic patterns.For the simulations we use the ns3 discrete-event network simulator.To make the resulting dataset appropriate for intrusion detection system benchmarking purposes we investigate the statistical characteristics of normal and intrusive traffic patterns.Finally we present a use case in which we validate our results.

Read the paper · More papers on PaperTik