Exploratory Data Analysis of a Network Telescope Traffic and Prediction of Port Probing Rates

12/23/2018
by   Mehdi Zakroum, et al.
0

Understanding the properties exhibited by large scale network probing traffic would improve cyber threat intelligence. In addition, the prediction of probing rates is a key feature for security practitioners in their endeavors for making better operational decisions and for enhancing their defense strategy skills. In this work, we study different aspects of the traffic captured by a /20 network telescope. First, we perform an exploratory data analysis of the collected probing activities. The investigation includes probing rates at the port level, services interesting top network probers and the distribution of probing rates by geolocation. Second, we extract the network probers exploration patterns. We model these behaviors using transition graphs decorated with probabilities of switching from a port to another. Finally, we assess the capacity of Non-stationary Autoregressive and Vector Autoregressive models in predicting port probing rates as a first step towards using more robust models for better forecasting performance.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/03/2021

Leveraging Open Threat Exchange (OTX) to Understand Spatio-Temporal Trends of Cyber Threats: Covid-19 Case Study

Understanding the properties exhibited by Spatial-temporal evolution of ...
research
12/27/2019

On Network Traffic Forecasting using Autoregressive Models

Various statistical analysis methods are studied for years to extract ac...
research
12/21/2022

5G Long-Term and Large-Scale Mobile Traffic Forecasting

It is crucial for the service provider to comprehend and forecast mobile...
research
03/02/2018

An Experimental Study of Factor Analysis over Cellular Network Data

Mobile Network Operators (MNOs) are evolving towards becoming data-drive...
research
09/07/2022

Large Scale Enrichment and Statistical Cyber Characterization of Network Traffic

Modern network sensors continuously produce enormous quantities of raw d...
research
08/04/2019

Boundary Defense against Cyber Threat for Power System Operation

The operation of power grids is becoming increasingly data-centric. Whil...
research
06/18/2021

Data Enforced: An Exploratory Impact Analysis of Automated Speed Enforcement in the District of Columbia

In 2015, the District of Columbia framed a Vision Zero mission and actio...

Please sign up or login with your details

Forgot password? Click here to reset