DocumentCode :
3055493
Title :
Network traffic classification with Self Organizing Maps
Author :
Kiziloren, Tevfik ; Germen, Emin
Author_Institution :
Anadolu Univ. Eskisehir, Eskisehir
fYear :
2007
fDate :
7-9 Nov. 2007
Firstpage :
1
Lastpage :
5
Abstract :
Anomaly detection in network traffic is one of the most challenging topics in the study of computer science and networking. This paper introduces a classification method for analyzing network traffic behavior. In order to distinguish the normal traffic with well-known anomalies such as port scanning and DOS attacks, Self Organizing Maps (SOMs), one of the well- known artificial neural network architecture, is used. The measurement of traffic is performed by using Simple Network Management Protocol (SNMP). In this work, it is proposed a SOM-based classifier to discriminate three types of network traffic as port scanning, heavy-download and the rests. It is worth to mention that impressively satisfactory results have been obtained. The method has also been enhanced to obtain better results by trying to find trajectories on the map with sliding the input vectors in time and developed an alarm mechanism. Here it is possible to detect whether consecutive trajectories are hit by one of the classes or not. The success rate of the system is approximate to certain.
Keywords :
computer network management; pattern classification; security of data; self-organising feature maps; telecommunication traffic; anomaly detection; artificial neural network architecture; network traffic classification; self organizing maps; simple network management protocol; Access protocols; Application software; Artificial neural networks; Computer science; IP networks; Identity management systems; Power system management; Self organizing feature maps; Switches; Telecommunication traffic; SNMP; SOM; anomaly detection; classification; component; intrusion detection; network traffic; neural networks; self organizing maps;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer and information sciences, 2007. iscis 2007. 22nd international symposium on
Conference_Location :
Ankara
Print_ISBN :
978-1-4244-1363-8
Electronic_ISBN :
978-1-4244-1364-5
Type :
conf
DOI :
10.1109/ISCIS.2007.4456852
Filename :
4456852
Link To Document :
بازگشت