Knowledge Discovery from Honeypot Data for Monitoring Malicious Attacks

被引:0
|
作者
Jin, Huidong [1 ,2 ]
de Vel, Olivier [3 ]
Zhang, Ke [1 ,2 ]
Liu, Nianjun [1 ,2 ]
机构
[1] NICTA Canberra Lab, Locked Bag 8001, Canberra, ACT 2601, Australia
[2] Australian Natl Univ, RSISE, Canberra, ACT 0200, Australia
[3] Def Sci & Technol Org, Command Ctrl Commun & Intelligence Div, Edinburg, SA 5111, Australia
基金
澳大利亚研究理事会;
关键词
Knowledge discovery; outlier detection; density-based cluster visualisation; botnet; honeypot data; Internet security;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Owing to the spread of worms and botnets, cyber attacks have significantly increased in volume, coordination and sophistication. Cheap rentable botnet services, e.g., have resulted in sophisticated botnets becoming an effective and popular tool for committing online crime these days. Honeypots, as information system traps, axe monitoring or deflecting malicious attacks on the Internet. To understand the attack patterns generated by botnets by virtue of the analysis of the data collected by honeypots, we propose an approach that integrates a clustering structure visualisation technique with outlier detection techniques. These techniques complement each other and provide end users both a big-picture view and actionable knowledge of high-dimensional data. We introduce KNOF (K-nearest Neighbours Outlier Factor) as the outlier definition technique to reach a trade-off between global and local outlier definitions, i.e., K-th-Nearest Neighbour (KNN) and Local Outlier Factor (LOF) respectively. We propose an algorithm to discover the most significant KNOF outliers. We implement these techniques in our hpdAnalyzer tool. The tool is successfully used to comprehend honeypot data. A series of experiments show that our proposed KNOF technique substantially outperforms LOF and, to a lesser degree, KNN for real-world honeypot data.
引用
收藏
页码:470 / +
页数:2
相关论文
共 50 条
  • [21] Knowledge discovery from data streams Introduction
    Gama, Joao
    Ganguly, Auroop
    Omitaomu, Olufemi
    Vatsavai, Raju
    Gaber, Mohamed
    INTELLIGENT DATA ANALYSIS, 2009, 13 (03) : 403 - 404
  • [22] From data mining to knowledge discovery in databases
    Fayyad, U
    PiatetskyShapiro, G
    Smyth, P
    AI MAGAZINE, 1996, 17 (03) : 37 - 54
  • [23] Knowledge Discovery from Mental Health Data
    Khan, Shahidul Islam
    Islam, Ariful
    Zahangir, Taiyeb Ibna
    Hoque, Abu Sayed Md Latiful
    PROCEEDING OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS, BIG DATA AND IOT (ICCBI-2018), 2020, 31 : 881 - 888
  • [24] Traffic Knowledge Discovery from AIS Data
    Pallotta, Giuliana
    Vespe, Michele
    Bryan, Karna
    2013 16TH INTERNATIONAL CONFERENCE ON INFORMATION FUSION (FUSION), 2013, : 1996 - 2003
  • [25] Knowledge Discovery from Social Graph Data
    Braun, Peter
    Cuzzocrea, Alfredo
    Leung, Carson K.
    Pazdor, Adam G. M.
    Tran, Kimberly
    KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS: PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE KES-2016, 2016, 96 : 682 - 691
  • [26] Knowledge discovery from imbalanced and noisy data
    Van Hulse, Jason
    Khoshgoftaar, Taghi
    DATA & KNOWLEDGE ENGINEERING, 2009, 68 (12) : 1513 - 1542
  • [27] Knowledge discovery process from sales data
    Yada, K
    INFORMATION TECHNOLOGY AND ORGANIZATIONS: TRENDS, ISSUES, CHALLENGES AND SOLUTIONS, VOLS 1 AND 2, 2003, : 684 - 687
  • [28] Knowledge Discovery from Earth Science Data
    Panigrahi, Sangram
    Verma, Kesari
    Tripathi, Priyanka
    Sharma, Rika
    2014 FOURTH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT), 2014, : 398 - 403
  • [29] Interpretable knowledge discovery from data with DC*
    Lucarelli, Marco
    Castiello, Ciro
    Fanelli, Anna M.
    Mencar, Corrado
    PROCEEDINGS OF THE 2015 CONFERENCE OF THE INTERNATIONAL FUZZY SYSTEMS ASSOCIATION AND THE EUROPEAN SOCIETY FOR FUZZY LOGIC AND TECHNOLOGY, 2015, 89 : 815 - 822
  • [30] Collaborative knowledge discovery & data mining: From knowledge to experience
    Horeis, Timo
    Sick, Bernhard
    2007 IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE AND DATA MINING, VOLS 1 AND 2, 2007, : 421 - 428