Feature Extraction Pipeline and Analysis of Suspicious Events in Large-Scale LANs for Cyberattack Categorization
Pawissakan Chirupphapa, Hiroshi Esaki, Hideya Ochiai · 2022
Cybersecurity is one of the most trending topics nowadays since more cyberattacks have been reported globally. A local area network (LAN) is commonly used in our daily life so that it should be crucially watched over. An analysis of network traffic captured by a network monitoring system can protect our LAN from cyberattacks. In this work, we propose SER-LAN which is the system for the analysis of suspicious events in LANs. In SER-LAN, the data pipeline extracts features of four protocols (ARP, TCP, UDP, and ICMP) from network traffic. In addition, an algorithm based on extracted features for categorization suspicious events in a LAN is presented. To demonstrate the data pipeline and the proposed algorithm, we show the analyses of suspicious events with real traffic from 20 LANs. According to the analysis, the top-3 most common suspicious events are network traffic with ICMP type 8, TCP port 445, and UDP port 137 respectively. Moreover, the result revealed that suspicious events which are the combination of 23 TCP ports and ICMP type 8 were observed in 5 LANs.