Sciweavers

GLOBECOM
2010
IEEE

Know Your Enemy, Know Yourself: Block-Level Network Behavior Profiling and Tracking

13 years 9 months ago
Know Your Enemy, Know Yourself: Block-Level Network Behavior Profiling and Tracking
Abstract. Gaining a better knowledge of one's own network is crucial to effectively manage and secure today's large, diverse campus and enterprise networks. Because of the large number of IP addresses (or hosts) and the prevalent use of dynamic IP addresses, profiling and tracking individual hosts within such large networks may not be effective nor scalable. In this paper we develop a novel methodology for capturing, characterizing, and tracking network activities at the block-level. To characterize block-level behaviors, we carefully select a port feature vector and capture the port activities of individual hosts within a block using a block-wise (host) port activity matrix (BPAM). Applying the SVD low-rank approximation technique, we obtain a low-dimensional subspace representation which captures the significant and typical host activities of the block. Using these subspace representations, we cluster and classify blocks to provide high-level descriptive labels to assist ne...
Esam Sharafuddin, Nan Jiang, Yu Jin, Zhi-Li Zhang
Added 11 Feb 2011
Updated 11 Feb 2011
Type Journal
Year 2010
Where GLOBECOM
Authors Esam Sharafuddin, Nan Jiang, Yu Jin, Zhi-Li Zhang
Comments (0)