Towards a User Network Profiling for Internal Security Top-k Rankings Similarity Measures Using K-means
摘要
Effective traffic control generally uses a variety of techniques for the classification, prediction, and monitoring of network traffic. This article proposes a method supported by the application of a technique to identify whether or not a network user is having normal behavior by analyzing host traffic using k-classification similarity measures. This article proposes an improvement of the estimation methodology of the K-means algorithm as an efficient solution oriented to cases with numerous groups and sizes (Wood P. ISTR Internet Security Threat Report. Symantec. [En línea] 2016.). The results of this study showed high accuracy using the joint approach with a group of 90 students from the Autonomous University of Guadalajara who were monitored for 30 min each using a proxy, demonstrating that the support vector classifier algorithm achieved 100% accuracy in this dataset. Once this information is obtained, the k-means algorithm is used to group users together and identify outliers exceed the upper limit of the k range.