loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: W. J. B. Beukema 1 ; T. Attema 2 and H. A. Schotanus 2

Affiliations: 1 University of Twente, Netherlands ; 2 The Netherlands Organisation for Applied Scientific Research (TNO), Netherlands

Keyword(s): Internal Network Traffic, Intrusion Detection, Host Clustering, Anomaly Detection, Advanced Persistent Threats.

Abstract: Internal network traffic is an undervalued source of information for detecting targeted attacks. Whereas most systems focus on the external border of the network, we observe that targeted attacks campaigns often involve internal network activity. To this end, we have developed techniques capable of detecting anomalous internal network behaviour. As a second contribution we propose an additional step in the model-based anomaly detection involving host clustering. Through host clustering, individual hosts are grouped together on the basis of their internal network behaviour. We argue that a behavioural model for each cluster, compared to a model for each host or a single model for all hosts, performs better in terms of detecting potentially malicious behaviour. We show that by applying this concept to internal network traffic, the detection performance for identifying malicious flows and hosts increases.

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.135.246.193

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Beukema, W.; Attema, T. and Schotanus, H. (2017). Internal Network Monitoring and Anomaly Detection through Host Clustering. In Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP 2017) - ForSE; ISBN 978-989-758-209-7; ISSN 2184-4356, SciTePress, pages 694-703. DOI: 10.5220/0006288606940703

@conference{forse17,
author={W. J. B. Beukema. and T. Attema. and H. A. Schotanus.},
title={Internal Network Monitoring and Anomaly Detection through Host Clustering},
booktitle={Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP 2017) - ForSE},
year={2017},
pages={694-703},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0006288606940703},
isbn={978-989-758-209-7},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP 2017) - ForSE
TI - Internal Network Monitoring and Anomaly Detection through Host Clustering
SN - 978-989-758-209-7
IS - 2184-4356
AU - Beukema, W.
AU - Attema, T.
AU - Schotanus, H.
PY - 2017
SP - 694
EP - 703
DO - 10.5220/0006288606940703
PB - SciTePress