Network Event Classification for Security of IT Infrastructure

D. Arora, P. Agathoklis, A. Loffler
{"title":"Network Event Classification for Security of IT Infrastructure","authors":"D. Arora, P. Agathoklis, A. Loffler","doi":"10.1109/WAINA.2018.00085","DOIUrl":null,"url":null,"abstract":"The number of devices connected over the Internet are expected to grow tremendously over the next few years. Maintaining secure communications between these network-enabled devices would be a major challenge. By carefully examining the events generated by these devices it is expected to gain some insights into their behavior and identifying if a device has been compromised. One of the major challenges in classifying the events generated by these devices is the inconsistencies in the data formats of these events and the separators between them. The approach presented in this paper is based on identifying and grouping similar events generated by these devices using an Agglomerative Hierarchical Clustering technique. To deal with the inconsistencies of formats and delimiters, some data preprocessing was used. The methodology proposed in this study was successful in identifying events stored in fifteen data files tested for analysis. The results indicate that the combination of text processing techniques in conjunction with machine learning based unsupervised learning offers promising alternatives in separating events generated by the network-enabled devices and, thus, facilitating a better understanding of their behavior and identifying potential security breaches.","PeriodicalId":296466,"journal":{"name":"2018 32nd International Conference on Advanced Information Networking and Applications Workshops (WAINA)","volume":"82 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 32nd International Conference on Advanced Information Networking and Applications Workshops (WAINA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WAINA.2018.00085","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The number of devices connected over the Internet are expected to grow tremendously over the next few years. Maintaining secure communications between these network-enabled devices would be a major challenge. By carefully examining the events generated by these devices it is expected to gain some insights into their behavior and identifying if a device has been compromised. One of the major challenges in classifying the events generated by these devices is the inconsistencies in the data formats of these events and the separators between them. The approach presented in this paper is based on identifying and grouping similar events generated by these devices using an Agglomerative Hierarchical Clustering technique. To deal with the inconsistencies of formats and delimiters, some data preprocessing was used. The methodology proposed in this study was successful in identifying events stored in fifteen data files tested for analysis. The results indicate that the combination of text processing techniques in conjunction with machine learning based unsupervised learning offers promising alternatives in separating events generated by the network-enabled devices and, thus, facilitating a better understanding of their behavior and identifying potential security breaches.
面向IT基础设施安全的网络事件分类
通过互联网连接的设备数量预计将在未来几年内大幅增长。维护这些支持网络的设备之间的安全通信将是一项重大挑战。通过仔细检查这些设备产生的事件,预计将获得对其行为的一些见解,并确定设备是否已被破坏。对这些设备生成的事件进行分类的主要挑战之一是这些事件的数据格式和它们之间的分隔符不一致。本文提出的方法是基于使用聚集分层聚类技术识别和分组这些设备产生的类似事件。为了解决格式和分隔符不一致的问题,对数据进行了预处理。本研究中提出的方法成功地识别了存储在15个数据文件中用于分析的事件。结果表明,将文本处理技术与基于机器学习的无监督学习相结合,为分离由网络设备生成的事件提供了有希望的替代方案,从而有助于更好地理解其行为并识别潜在的安全漏洞。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信