DocumentCode :
260370
Title :
A Session Based Approach for Aggregating Network Traffic Data -- The SANTA Dataset
Author :
Wheelus, Charles ; Khoshgoftaar, Taghi M. ; Zuech, Richard ; Najafabadi, Maryam M.
Author_Institution :
Florida Atlantic Univ., Boca Raton, FL, USA
fYear :
2014
fDate :
10-12 Nov. 2014
Firstpage :
369
Lastpage :
378
Abstract :
This paper compares and contrasts the most widely used network security datasets, evaluating their efficacy in providing a benchmark for intrusion and anomaly detection systems. The antiquated nature of some of the most widely used datasets along with their inadequacies is examined and used as a basis for discussion of a new approach to analyzing network traffic data. Live network traffic is collected that consists of real normal traffic and both real and penetration testing attack data. Attack data is then inspected and labeled by means of manual analysis. While network attacks and anomaly features vary widely, they share some commonalities that are examined here. Among these are: self-similarity convergence, periodicity, and repetition. Further, the knowledge inherent in the definition of network boundaries and advertised services can provide crucial context that allows the network analyst to consider self-aware attributes when examining network traffic sessions. To these ends the Session Aggregation for Network Traffic Analysis (SANTA) dataset is proposed. The motivation and the methodology of collection, aggregation and evaluation of the raw data are presented, as well as the conceptualization of the SANTA attributes and advantages provided by this approach.
Keywords :
aggregation; data analysis; fractals; medical information systems; security of data; SANTA dataset; anomaly detection systems; intrusion detection systems; network security datasets; self-similarity convergence; session aggregation for network traffic analysis dataset; Context; IP networks; Internet; Ports (Computers); Security; Telecommunication traffic; Testing; Network traffic data; intrusion detection; periodicity;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Bioinformatics and Bioengineering (BIBE), 2014 IEEE International Conference on
Conference_Location :
Boca Raton, FL
Type :
conf
DOI :
10.1109/BIBE.2014.72
Filename :
7033608
Link To Document :
بازگشت