Clustering and monitoring edge behaviour in enterprise network traffic
File(s)IEEE_Schon_Adams_Evangelou.pdf (766.3 KB)
Accepted version
Author(s)
Schon, C
Adams, NM
Evangelou, M
Type
Conference Paper
Abstract
This paper takes an unsupervised learning approach for monitoring edge activity within an enterprise computer network. Using NetFlow records, features are gathered across the active connections (edges) in 15-minute time windows. Then, edges are grouped into clusters using the k-means algorithm. This process is repeated over contiguous windows. A series of informative indicators are derived by examining the relationship of edges with the observed cluster structure. This leads to an intuitive method for monitoring network behaviour and a temporal description of edge behaviour at global and local levels.
Date Issued
2017-08-18
Date Acceptance
2017-05-28
Citation
2017 IEEE International Conference on Intelligence and Security Informatics (ISI), 2017, pp.31-36
Publisher
IEEE
Start Page
31
End Page
36
Journal / Book Title
2017 IEEE International Conference on Intelligence and Security Informatics (ISI)
Copyright Statement
© 2017 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
Source
IEEE International Conference on Intelligence and Security Informatics
Subjects
Science & Technology
Technology
Computer Science, Theory & Methods
Engineering, Electrical & Electronic
Computer Science
Engineering
Cyber-security
clustering
NetFlow
Publication Status
Published
Start Date
2017-07-22
Finish Date
2017-07-24
Coverage Spatial
Beijing, China
Date Publish Online
2017-08-18