Network Attack Detection Based on Peer-to-Peer Clustering of SNMP Data

被引:0
|
作者
Cerroni, Walter [1 ]
Monti, Gabriele [1 ]
Moro, Gianluca [1 ]
Ramilli, Marco [1 ]
机构
[1] DEIS Univ Bologna, I-47521 Cesena, FC, Italy
关键词
Network security; distributed intrusion detection; SNMP; data mining; data clustering; peer-to-peer; ANOMALY DETECTION;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Network intrusion detection is a key security issue that can be tackled by means of different approaches. This paper describes a novel methodology for network attack detection based on the use of data mining techniques to process traffic information collected by a monitoring station from a set of hosts using the Simple Network Management Protocol (SNMP). The proposed approach, adopting unsupervised clustering techniques, allows to effectively distinguish normal traffic behavior from malicious network activity and to determine with very good accuracy what kind of attack is being perpetrated. Several monitoring stations are then interconnected according to any peer-to-peer network in order to share the knowledge base acquired with the proposed methodology, thus increasing the detection capabilities. An experimental test-bed has been implemented, which reproduces the case of a real web server under several attack techniques. Results of the experiments show the effectiveness of the proposed solution, with no detection failures of true attacks and very low false-positive rates (i.e. false alarms).
引用
收藏
页码:417 / 430
页数:14
相关论文
共 50 条
  • [21] Connectivity based node clustering in decentralized peer-to-peer networks
    Ramaswamy, L
    Gedik, B
    Liu, L
    THIRD INTERNATIONAL CONFERENCE ON PEER-TO-PEER COMPUTING (P2P2003), PROCEEDINGS, 2003, : 66 - 73
  • [22] Swarm-based distributed clustering in peer-to-peer systems
    Folino, Gianluigi
    Forestiero, Agostino
    Spezzano, Giandomenico
    ARTIFICIAL EVOLUTION, 2006, 3871 : 37 - 48
  • [23] Ontology-based clustering and routing in peer-to-peer networks
    Li, J
    Vuong, S
    PDCAT 2005: SIXTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2005, : 791 - 795
  • [24] A new peer-to-peer network
    Harutyunyan, Hovhannes
    He, Junlei
    FIFTH ANNUAL IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS, PROCEEDINGS, 2007, : 120 - +
  • [25] Diffusion on the Peer-to-Peer Network
    Riposo, Julien
    JOURNAL OF RISK AND FINANCIAL MANAGEMENT, 2022, 15 (02)
  • [26] A “cluster” based search scheme in peer-to-peer network
    Li Zhen-wu
    Yang Jian
    Shi Xu-dong
    Bai Ying-cai
    Journal of Zhejiang University-SCIENCE A, 2003, 4 (5): : 549 - 554
  • [27] Collaborative work model based on peer-to-peer network
    JIANG Jian-zhong a
    Journal of Chongqing University(English Edition), 2007, (02) : 130 - 134
  • [28] Practical Implementation of Femtolet Based Peer-to-Peer Network
    Deepsubhra Guha Roy
    Anwesha Mukherjee
    Debashis De
    Satish Narayana Srirama
    Wireless Personal Communications, 2019, 108 : 2477 - 2498
  • [29] Peer-to-Peer Overlay Network Based on Swarm Intelligence
    Sesum-Cavic, Vesna
    Kuehn, Eva
    ENGINEERING SOCIETIES IN THE AGENTS WORLD X, 2009, 5881 : 65 - 67
  • [30] An Anonymous Peer-to-Peer based Online Social Network
    Jain, Ina
    Gorantla, M. Choudary
    Saxena, Ashutosh
    2011 ANNUAL IEEE INDIA CONFERENCE (INDICON-2011): ENGINEERING SUSTAINABLE SOLUTIONS, 2011,