Discrete Mathematical Approaches to Graph-Based Traffic Analysis
Conference
·
OSTI ID:1222143
Modern cyber defense and anlaytics requires general, formal models of cyber systems. Multi-scale network models are prime candidates for such formalisms, using discrete mathematical methods based in hierarchically-structured directed multigraphs which also include rich sets of labels. An exemplar of an application of such an approach is traffic analysis, that is, observing and analyzing connections between clients, servers, hosts, and actors within IP networks, over time, to identify characteristic or suspicious patterns. Towards that end, NetFlow (or more generically, IPFLOW) data are available from routers and servers which summarize coherent groups of IP packets flowing through the network. In this paper, we consider traffic analysis of Netflow using both basic graph statistics and two new mathematical measures involving labeled degree distributions and time interval overlap measures. We do all of this over the VAST test data set of 96M synthetic Netflow graph edges, against which we can identify characteristic patterns of simulated ground-truth network attacks.
- Research Organization:
- Pacific Northwest National Laboratory (PNNL), Richland, WA (US)
- Sponsoring Organization:
- USDOE
- DOE Contract Number:
- AC05-76RL01830
- OSTI ID:
- 1222143
- Report Number(s):
- PNNL-SA-101858
- Country of Publication:
- United States
- Language:
- English
Similar Records
Massive Scale Cyber Traffic Analysis: A Driver for Graph Database Research
A Network Management System for Handling Scientific Data Flows
Graph anomalies in cyber communications
Conference
·
Wed Jun 19 00:00:00 EDT 2013
·
OSTI ID:1089074
A Network Management System for Handling Scientific Data Flows
Journal Article
·
Fri Oct 10 20:00:00 EDT 2014
· Journal of Network and Systems Management
·
OSTI ID:1532178
Graph anomalies in cyber communications
Conference
·
Mon Jan 10 23:00:00 EST 2011
·
OSTI ID:1046548