TY - GEN
T1 - Network abnormal behaviour analysis system
AU - Choi, Sunoh
AU - Choi, Yangseo
AU - Lee, Jooyoung
AU - Kim, Jonghyun
AU - Kim, Ikkyun
N1 - Publisher Copyright:
© 2017 Global IT Research Institute - GiRI.
PY - 2017/3/29
Y1 - 2017/3/29
N2 - As cyber attacks have increased in recent years, network forensics, which collects and analyses network packets as well as digital forensics, has been studied. However, high-speed networks such as 1 or 10 Gbps networks have many network flows. For example, a 1 Gbps network has hundreds of millions of network flows per day. Analysing network traffic in this situation is very difficult and time-consuming. In this paper, we propose a system that can analyse network abnormal behaviour quickly and easily. We first propose a system that stores the TCP flag when generating network flows. Second, we present some ways to use the TCP flag in network flows to analyse network anomalies such as persistent outbound connections.
AB - As cyber attacks have increased in recent years, network forensics, which collects and analyses network packets as well as digital forensics, has been studied. However, high-speed networks such as 1 or 10 Gbps networks have many network flows. For example, a 1 Gbps network has hundreds of millions of network flows per day. Analysing network traffic in this situation is very difficult and time-consuming. In this paper, we propose a system that can analyse network abnormal behaviour quickly and easily. We first propose a system that stores the TCP flag when generating network flows. Second, we present some ways to use the TCP flag in network flows to analyse network anomalies such as persistent outbound connections.
KW - Analysis
KW - Network flow
UR - https://www.scopus.com/pages/publications/85018471323
U2 - 10.23919/ICACT.2017.7890055
DO - 10.23919/ICACT.2017.7890055
M3 - Conference paper
AN - SCOPUS:85018471323
T3 - International Conference on Advanced Communication Technology, ICACT
SP - 49
EP - 52
BT - 19th International Conference on Advanced Communications Technology
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 19th International Conference on Advanced Communications Technology, ICACT 2017
Y2 - 19 February 2017 through 22 February 2017
ER -