DocumentCode
230516
Title
Unsupervised classification and characterization of honeypot attacks
Author
Owezarski, Philippe
Author_Institution
LAAS, Toulouse, France
fYear
2014
fDate
17-21 Nov. 2014
Firstpage
10
Lastpage
18
Abstract
Monitoring communication networks and their traffic is of essential importance for estimating the risk in the Internet, and therefore designing suited protection systems for computer networks. Network and traffic analysis can be done thanks to measurement devices or honeypots. However, analyzing the huge amount of gathered data, and characterizing the anomalies and attacks contained in these traces remain complex and time consuming tasks, done by network and security experts using poorly automatized tools, and are consequently slow and costly. In this paper, we present an unsupervised method for classification and characterization of security related anomalies and attacks occurring in honeypots. This as automatized as possible method does not need any attack signature database, learning phase, or labeled traffic. This corresponds to a major step towards autonomous security systems. This paper also shows how it is possible from anomalies characterization results to infer filtering rules that could serve for automatically configuring network routers, switches or firewalls.
Keywords
Internet; computer network security; pattern classification; telecommunication network routing; telecommunication traffic; unsupervised learning; Internet; autonomous security systems; communication network monitoring; computer network protection systems; firewalls; honeypot attacks; network routers; switches; traffic analysis; unsupervised anomaly characterization; unsupervised anomaly classification; Algorithm design and analysis; Clustering algorithms; Correlation; IP networks; Internet; Partitioning algorithms; Security; Anomaly classification; Honeypot attack detection; autonomous security systems; unsupervised machine learning;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and Service Management (CNSM), 2014 10th International Conference on
Conference_Location
Rio de Janeiro
Type
conf
DOI
10.1109/CNSM.2014.7014136
Filename
7014136
Link To Document