Automatic Anomaly Detection by Network Traffic Analysis
Subhajit Sahana, Moitri Dey, Shyam Sai Ganesh, Piyush Kumar, Rojalina Priyadarshini, Nachiketa Tarasia · 2023
Monitoring the network traffic and analyzing it becomes essential in present scenario with an increase in the internet usage. Network traffic analysis is the process of capturing network traffic and monitoring it closely to determine what is happening on the network and notifies the administrator whenever there is an outage. The data packets are analyzed by a network analyzer and the network traffic is displayed in readable format. Like other tools, a network analyzer is also a two-edged sword used for good and bad intentions. While the network system and security experts use it to solve the problem and monitor the network, the intermediaries use the network analysis for malicious purposes. For network administrators, there are a variety of network monitoring tools available that use various monitoring techniques to monitor and analyses network data. In this work, an effort has been made to create an integrated and comprehensive automatic tool which can capture the network traffic and prevent the network from several attacks. A customized rule-based tool is developed using Python which is able to detect three types of attacks like port scan, Denial of service (DoS) and Distributed denial of service (DDoS) attack in a network.