Back to Search
Start Over
Applying MMD Data Mining to Match Network Traffic for Stepping-Stone Intrusion Detection
- Source :
- Sensors, Volume 21, Issue 22, Sensors (Basel, Switzerland), Sensors, Vol 21, Iss 7464, p 7464 (2021)
- Publication Year :
- 2021
- Publisher :
- Multidisciplinary Digital Publishing Institute, 2021.
-
Abstract
- A long interactive TCP connection chain has been widely used by attackers to launch their attacks and thus avoid detection. The longer a connection chain, the higher the probability the chain is exploited by attackers. Round-trip Time (RTT) can represent the length of a connection chain. In order to obtain the RTTs from the sniffed Send and Echo packets in a connection chain, matching the Sends and Echoes is required. In this paper, we first model a network traffic as the collection of RTTs and present the rationale of using the RTTs of a connection chain to represent the length of the chain. Second, we propose applying MMD data mining algorithm to match TCP Send and Echo packets collected from a connection. We found that the MMD data mining packet-matching algorithm outperforms all the existing packet-matching algorithms in terms of packet-matching rate including sequence number-based algorithm, Yang’s approach, Step-function, Packet-matching conservative algorithm and packet-matching greedy algorithm. The experimental results from our local area networks showed that the packet-matching accuracy of the MMD algorithm is 100%. The average packet-matching rate of the MMD algorithm obtained from the experiments conducted under the Internet context can reach around 94%. The MMD data mining packet-matching algorithm can fix the issue of low packet-matching rate faced by all the existing packet-matching algorithms including the state-of-the-art algorithm. It is applicable to network-based stepping-stone intrusion detection.
- Subjects :
- Matching (graph theory)
Computer science
Network security
intrusion detection
Context (language use)
TP1-1185
Intrusion detection system
computer.software_genre
Biochemistry
Article
Analytical Chemistry
network security
Electrical and Electronic Engineering
Greedy algorithm
Instrumentation
MMD
Network packet
business.industry
Chemical technology
Echo (computing)
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS
packet-matching
Local area network
data mining
Atomic and Molecular Physics, and Optics
Data mining
business
computer
stepping-stone
Algorithms
Subjects
Details
- Language :
- English
- ISSN :
- 14248220
- Database :
- OpenAIRE
- Journal :
- Sensors
- Accession number :
- edsair.doi.dedup.....134025e5b8a9fe7ac6903862d2584a59
- Full Text :
- https://doi.org/10.3390/s21227464