Title :
A multi-variate classification approach for the detection of illicit traffic
Author :
Rocha, Eduardo ; Salvador, Paulo ; Nogueira, António
Author_Institution :
Inst. de Telecomun., Univ. of Aveiro, Aveiro, Portugal
Abstract :
Nowadays, all commercial and personal activities rely almost exclusively on digital information that is constantly accessed, exchanged and archived over the Internet. These facts attracted the interest of the hacker community, driven by the will to obtain profits by exploiting many existing vulnerabilities. Consequently, the number of reported attacks increased dramatically, together with the financial losses associated to them. Botnets have become the cornerstone of on-line criminal activities and can be considered the most serious threat to the Internet. Current detection and prevention methodologies are not able to assure a complete protection as the complexity and subtlety of security attacks and generated illicit traffic grow: these include the encapsulation of illicit traffic in legitimate communications or the replication of normal communications profiles in order to bypass the various network defense mechanisms. Consequently, novel identification and prevention approaches must be proposed and studied in order to address all these issues. In this paper, we present a novel detection methodology that, by building high-level traffic profiles and modeling their embedded multi-scaling dynamics, can accurately identify the components created by illicit applications. The analysis of captured traffic samples over sliding time-windows allows the identification of illicit traffic components that are hidden in legitimate communications. The proposed methodology is also able to cope with the most stringent confidentially restrictions that typically prevent the use of other detection tools.
Keywords :
Internet; security of data; telecommunication security; telecommunication traffic; high-level traffic profiles; illicit traffic; multiscaling dynamics; multivariate classification approach; security attacks; sliding time-windows; Cryptography; Data mining; Discrete wavelet transforms; Internet; Protocols; Stochastic processes; Illicit traffic; Internet applications; multi-scale analysis; traffic classification;
Conference_Titel :
Software, Telecommunications and Computer Networks (SoftCOM), 2011 19th International Conference on
Conference_Location :
Split
Print_ISBN :
978-1-4577-1439-9