Internet Resource Analysis for Cyber Threat Source Detection

Sergey V. Isaev, Denis Doncov · 2024

An important aspect of the successful functioning of a modern organization is the security of its computer network. There are various tools for preventing cyber threats and analysis of visited Internet resources, but their productivity and applicability are highly dependent on the capacity of input data. The article discusses the existing methods for detecting network threats by analyzing proxy server logs using the example of the Krasnoyarsk Scientific Center of the Siberian Branch of the Russian Academy of Sciences. The division of Internet users into thematic groups to detect anomalies is studied. A method for clustering Internet resources is proposed, aimed at reducing the volume of input data by excluding groups of safe Internet resources or selecting only suspicious Internet resources. It consists of stages: data preprocessing, user session selection, data analysis and interpretation of the results. The initial data is the log records of the proxy server. The result of the work are Internet resources grouped into a certain number of unnamed groups. They can be interpreted by analyzing the most popular Internet resources in each group. The method has many settings at each stage, which allows you to configure it for any format and specifics of the input data. It can serve as an additional preprocessing step to reduce the volume of input data and to identify data anomaly.

Read the paper · More papers on PaperTik