• DocumentCode
    2127175
  • Title

    A multi-variate classification approach for the detection of illicit traffic

  • Author

    Rocha, Eduardo ; Salvador, Paulo ; Nogueira, António

  • Author_Institution
    Inst. de Telecomun., Univ. of Aveiro, Aveiro, Portugal
  • fYear
    2011
  • fDate
    15-17 Sept. 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Nowadays, all commercial and personal activities rely almost exclusively on digital information that is constantly accessed, exchanged and archived over the Internet. These facts attracted the interest of the hacker community, driven by the will to obtain profits by exploiting many existing vulnerabilities. Consequently, the number of reported attacks increased dramatically, together with the financial losses associated to them. Botnets have become the cornerstone of on-line criminal activities and can be considered the most serious threat to the Internet. Current detection and prevention methodologies are not able to assure a complete protection as the complexity and subtlety of security attacks and generated illicit traffic grow: these include the encapsulation of illicit traffic in legitimate communications or the replication of normal communications profiles in order to bypass the various network defense mechanisms. Consequently, novel identification and prevention approaches must be proposed and studied in order to address all these issues. In this paper, we present a novel detection methodology that, by building high-level traffic profiles and modeling their embedded multi-scaling dynamics, can accurately identify the components created by illicit applications. The analysis of captured traffic samples over sliding time-windows allows the identification of illicit traffic components that are hidden in legitimate communications. The proposed methodology is also able to cope with the most stringent confidentially restrictions that typically prevent the use of other detection tools.
  • Keywords
    Internet; security of data; telecommunication security; telecommunication traffic; high-level traffic profiles; illicit traffic; multiscaling dynamics; multivariate classification approach; security attacks; sliding time-windows; Cryptography; Data mining; Discrete wavelet transforms; Internet; Protocols; Stochastic processes; Illicit traffic; Internet applications; multi-scale analysis; traffic classification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software, Telecommunications and Computer Networks (SoftCOM), 2011 19th International Conference on
  • Conference_Location
    Split
  • Print_ISBN
    978-1-4577-1439-9
  • Type

    conf

  • Filename
    6064390