Description
We study the discriminant power of network features for traffic analysis, classification and attack detection network level. We compare existing feature sets previouly proposed in the literature and study new proposals. We aim to obtain lightweight vectors able to deal with modern network traffic challenges, such as: encryption, big data, stream data, fast extraction and preprocessing, prompt responses, host/flow/network behaviour modeling, network monitoring, etc.
Experiments
Scripts, datasets and experiments to download for reproducibility and further testing:
- Comparions of lightweigh vectors for attack detection (October 2018)
Publications
If your are using any of the material below please cite the corresponding publication.
Comparison of lightweigh feature vectors:
- Fares Meghdouri, Tanja Zseby and Félix Iglesias, Analysis of Lightweight Feature Vectors for Attack Detection in Network Traffic. (Pending publication)
Feature set obtained by meta-analysis on past research:
AGM vector:
Time Activity vector:
Study of features for attack detection: