Detecting unmanaged and unauthorized devices on the network with long short-term memory network | IEEE Conference Publication | IEEE Xplore

Detecting unmanaged and unauthorized devices on the network with long short-term memory network


Abstract:

Unmanaged and unauthorized devices present in a corporate network pose potential security risk. Gaining insights into these devices starts with their identification. Howe...Show More

Abstract:

Unmanaged and unauthorized devices present in a corporate network pose potential security risk. Gaining insights into these devices starts with their identification. However, there have been few studies that recognize these devices among tens to hundreds of thousands of devices typically present on a large corporate network. On the other hand, names of the unmanaged and unauthorized devices are telling, as they do not necessarily conform to the existing known and unknown naming conventions followed by the majority of machines managed by a corporation. This work examines the lexical content of networked device names to flag devices with unusual names that are worth noting. We show how a long short-term memory (LSTM) network learns from the device names to flag the anomalously named devices. We demonstrate how the method offers a practical solution to detect unmanaged and unauthorized devices in real-world corporate networks.
Date of Conference: 10-13 December 2018
Date Added to IEEE Xplore: 24 January 2019
ISBN Information:
Conference Location: Seattle, WA, USA

Contact IEEE to Subscribe

References

References is not available for this document.