Application of Exploratory Multivariate Analysis for Network Security

V. Rao Vemuri · 2005

There are many ways to study, analyze, visualize and detect network traffic anomalies. Some of these are quite successful. However, it is difficult to compare the results obtained from these studies and to define the merits and demerits of each method. This difficulty is exacerbated while comparing visualization methods. A primary reason for this difficulty is the heterogeneous nature of the development process of these methods, as they do not use a common framework for the development and testing. This study uses the S language for statistical computing and graphics as a unified framework for evaluating the applicability of seven exploratory multivariate analysis methods for anomaly detection and visualization. The methods are used to study, visualize and possibly detect computer network attacks. The k-means, hierarchical clustering, self-organizing maps, principal component analysis, independent component analysis, stars plots and mosaic plots are used to analyze and visualize selected network attacks from the DARPA 1998 Intrusion detection evaluation data set. Visualization techniques associated with each method provide more in-depth representation of the nature of the network traffic with each method having its unique view of the data. Some of the results obtained may be used in identifying trends in the behavioral change in the traffic characteristics. Using this unified framework, a comparison of the performance, feature, graphical representation and applicability of each method is possible.

Read the paper · More papers on PaperTik