DocumentCode :
2127175
Title :
A multi-variate classification approach for the detection of illicit traffic
Author :
Rocha, Eduardo ; Salvador, Paulo ; Nogueira, António
Author_Institution :
Inst. de Telecomun., Univ. of Aveiro, Aveiro, Portugal
fYear :
2011
fDate :
15-17 Sept. 2011
Firstpage :
1
Lastpage :
6
Abstract :
Nowadays, all commercial and personal activities rely almost exclusively on digital information that is constantly accessed, exchanged and archived over the Internet. These facts attracted the interest of the hacker community, driven by the will to obtain profits by exploiting many existing vulnerabilities. Consequently, the number of reported attacks increased dramatically, together with the financial losses associated to them. Botnets have become the cornerstone of on-line criminal activities and can be considered the most serious threat to the Internet. Current detection and prevention methodologies are not able to assure a complete protection as the complexity and subtlety of security attacks and generated illicit traffic grow: these include the encapsulation of illicit traffic in legitimate communications or the replication of normal communications profiles in order to bypass the various network defense mechanisms. Consequently, novel identification and prevention approaches must be proposed and studied in order to address all these issues. In this paper, we present a novel detection methodology that, by building high-level traffic profiles and modeling their embedded multi-scaling dynamics, can accurately identify the components created by illicit applications. The analysis of captured traffic samples over sliding time-windows allows the identification of illicit traffic components that are hidden in legitimate communications. The proposed methodology is also able to cope with the most stringent confidentially restrictions that typically prevent the use of other detection tools.
Keywords :
Internet; security of data; telecommunication security; telecommunication traffic; high-level traffic profiles; illicit traffic; multiscaling dynamics; multivariate classification approach; security attacks; sliding time-windows; Cryptography; Data mining; Discrete wavelet transforms; Internet; Protocols; Stochastic processes; Illicit traffic; Internet applications; multi-scale analysis; traffic classification;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software, Telecommunications and Computer Networks (SoftCOM), 2011 19th International Conference on
Conference_Location :
Split
Print_ISBN :
978-1-4577-1439-9
Type :
conf
Filename :
6064390
Link To Document :
بازگشت