• DocumentCode
    725891
  • Title

    A kernel based Atanassov´s intuitionistic fuzzy clustering for network forensics and intrusion detection

  • Author

    Panwar, Anupam

  • Author_Institution
    Symantec Corp., Bangalore, India
  • fYear
    2015
  • fDate
    June 28 2015-July 1 2015
  • Firstpage
    107
  • Lastpage
    112
  • Abstract
    Malware or virus is one of the most significant security threats in internet. There are mainly two types of successful (partially) solutions available. One is anti-virus and other is back listing. This kind of detection generally depends on the existing malware or virus signature database. Cyber-criminals bypass defenses by generating variants of their malware program. Traditional approach has limitations such as unable to detect zero day threats or generate so many false alerts et al. To overcome these difficulties, a system is built based on Atanassov´s intuitionistic fuzzy set (AIFS) theory based clustering method that takes care of these problems in a robust way. It not only raises an alert for new kind of malware but also decreases the number of false alerts. This is done by giving it decision making intelligence. There is not much work done in the field of network forensics using AIFS theory. This method clusters the malwares/viruses with high accuracy on the basis of severity. Experiments are performed on several pcap files with malware traffic to assess the performance and accuracy of the method.
  • Keywords
    digital forensics; fuzzy set theory; invasive software; pattern clustering; AIFS theory based clustering method; Atanassov intuitionistic fuzzy set theory; intrusion detection; malware program; malware signature database; malware traffic; network forensics; virus signature database; Clustering algorithms; Entertainment industry; Internet; Kernel; Malware; Uniform resource locators; Atanassov´s Intuitionistic Fuzzy Set; Hesitation Degree; Intuitionistic Fuzzy Cluster; Malware detection; Network Forensics; Network Packets Analysis; pcap Files;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Science (ICIS), 2015 IEEE/ACIS 14th International Conference on
  • Conference_Location
    Las Vegas, NV
  • Type

    conf

  • DOI
    10.1109/ICIS.2015.7166578
  • Filename
    7166578