Disassortativity of computer networks
File(s) dissasortivity.pdf (493.31 KB)
Accepted version
Author(s)
Rubin-Delanchy, P
HEARD, NA
Type
Conference Paper
Abstract
Network data is ubiquitous in cyber-security applications. Accurately modelling such data allows discovery of anomalous edges, subgraphs or paths, and is key to many signature-free cyber-security analytics. We present a recurring property of graphs originating from cyber-security applications, often considered a ‘corner case’ in the main literature on network data analysis, that greatly affects the performance of standard ‘off-the-shelf’ techniques. This is the property that similarity, in terms of network behaviour, does not imply connectivity, and in fact the reverse is often true. We call this disassortivity. The phenomenon is illustrated using network flow data collected on an enterprise network, and we show how Big Data analytics designed to detect unusual connectivity patterns can be improved.
Date Issued
2016-11-17
Date Acceptance
2016-08-18
Citation
2016
ISBN
978-1-5090-3865-7
Publisher
IEEE
Copyright Statement
© 2016 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
Source
IEEE International Conference on Intelligence and Security Informatics
Publication Status
Published
Start Date
2016-09-28
Finish Date
2016-09-30
Coverage Spatial
Arizona, USA
