Skip to main navigation Skip to search Skip to main content

Network abnormal behaviour analysis system

  • Sunoh Choi
  • , Yangseo Choi
  • , Jooyoung Lee
  • , Jonghyun Kim
  • , Ikkyun Kim
  • Electronics and Telecommunications Research Institute

Research output: Contribution to conferenceConference paperpeer-review

Abstract

As cyber attacks have increased in recent years, network forensics, which collects and analyses network packets as well as digital forensics, has been studied. However, high-speed networks such as 1 or 10 Gbps networks have many network flows. For example, a 1 Gbps network has hundreds of millions of network flows per day. Analysing network traffic in this situation is very difficult and time-consuming. In this paper, we propose a system that can analyse network abnormal behaviour quickly and easily. We first propose a system that stores the TCP flag when generating network flows. Second, we present some ways to use the TCP flag in network flows to analyse network anomalies such as persistent outbound connections.

Original languageEnglish
Title of host publication19th International Conference on Advanced Communications Technology
Subtitle of host publicationOpening Era of Smart Society, ICACT 2017 - Proceeding
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages49-52
Number of pages4
ISBN (Electronic)9788996865094
DOIs
StatePublished - 2017.03.29
Event19th International Conference on Advanced Communications Technology, ICACT 2017 - Pyeongchang, Korea, Republic of
Duration: 2017.02.192017.02.22

Publication series

NameInternational Conference on Advanced Communication Technology, ICACT
ISSN (Print)1738-9445

Conference

Conference19th International Conference on Advanced Communications Technology, ICACT 2017
Country/TerritoryKorea, Republic of
CityPyeongchang
Period17.02.1917.02.22

Keywords

  • Analysis
  • Network flow

Fingerprint

Dive into the research topics of 'Network abnormal behaviour analysis system'. Together they form a unique fingerprint.

Cite this