• DocumentCode
    230516
  • Title

    Unsupervised classification and characterization of honeypot attacks

  • Author

    Owezarski, Philippe

  • Author_Institution
    LAAS, Toulouse, France
  • fYear
    2014
  • fDate
    17-21 Nov. 2014
  • Firstpage
    10
  • Lastpage
    18
  • Abstract
    Monitoring communication networks and their traffic is of essential importance for estimating the risk in the Internet, and therefore designing suited protection systems for computer networks. Network and traffic analysis can be done thanks to measurement devices or honeypots. However, analyzing the huge amount of gathered data, and characterizing the anomalies and attacks contained in these traces remain complex and time consuming tasks, done by network and security experts using poorly automatized tools, and are consequently slow and costly. In this paper, we present an unsupervised method for classification and characterization of security related anomalies and attacks occurring in honeypots. This as automatized as possible method does not need any attack signature database, learning phase, or labeled traffic. This corresponds to a major step towards autonomous security systems. This paper also shows how it is possible from anomalies characterization results to infer filtering rules that could serve for automatically configuring network routers, switches or firewalls.
  • Keywords
    Internet; computer network security; pattern classification; telecommunication network routing; telecommunication traffic; unsupervised learning; Internet; autonomous security systems; communication network monitoring; computer network protection systems; firewalls; honeypot attacks; network routers; switches; traffic analysis; unsupervised anomaly characterization; unsupervised anomaly classification; Algorithm design and analysis; Clustering algorithms; Correlation; IP networks; Internet; Partitioning algorithms; Security; Anomaly classification; Honeypot attack detection; autonomous security systems; unsupervised machine learning;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Management (CNSM), 2014 10th International Conference on
  • Conference_Location
    Rio de Janeiro
  • Type

    conf

  • DOI
    10.1109/CNSM.2014.7014136
  • Filename
    7014136