Behaviour analysis in network communications is a growing research field especially for intrusion detection systems due to the increasing complexity of cyberattacks. Most advanced techniques to detect cyberattacks are using machine learning to identify abnormal behaviour and to define the baseline network. However, normal user actions in computer network communications, to the best of our knowledge, have yet to be fully defined and formally modelled. Studies focus on defining and identifying cyberattacks without much consideration of “normal" or legitimate actions. But, identifying activities from network communications is extremely useful for the early detection of cyberattacks. Network traffic classification studies consider high level interactions (TOR browsing, streaming, ...) without examining and understand real human activities and goals. An accurate modelling approach describing human activities from network communications is proposed. Activity theory has been chosen as the conceptual framework for our formal model. The approach has been used for generating a first dataset containing pertinent daily activities to highlight the potential of the approach.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Modelling Approach for Identifying Normal Activities in Computer Network Communications

  • Maxence Lannuzel,
  • David Brosset

摘要

Behaviour analysis in network communications is a growing research field especially for intrusion detection systems due to the increasing complexity of cyberattacks. Most advanced techniques to detect cyberattacks are using machine learning to identify abnormal behaviour and to define the baseline network. However, normal user actions in computer network communications, to the best of our knowledge, have yet to be fully defined and formally modelled. Studies focus on defining and identifying cyberattacks without much consideration of “normal" or legitimate actions. But, identifying activities from network communications is extremely useful for the early detection of cyberattacks. Network traffic classification studies consider high level interactions (TOR browsing, streaming, ...) without examining and understand real human activities and goals. An accurate modelling approach describing human activities from network communications is proposed. Activity theory has been chosen as the conceptual framework for our formal model. The approach has been used for generating a first dataset containing pertinent daily activities to highlight the potential of the approach.