A Modelling Approach for Identifying Normal Activities in Computer Network Communications
摘要
Behaviour analysis in network communications is a growing research field especially for intrusion detection systems due to the increasing complexity of cyberattacks. Most advanced techniques to detect cyberattacks are using machine learning to identify abnormal behaviour and to define the baseline network. However, normal user actions in computer network communications, to the best of our knowledge, have yet to be fully defined and formally modelled. Studies focus on defining and identifying cyberattacks without much consideration of “normal" or legitimate actions. But, identifying activities from network communications is extremely useful for the early detection of cyberattacks. Network traffic classification studies consider high level interactions (TOR browsing, streaming, ...) without examining and understand real human activities and goals. An accurate modelling approach describing human activities from network communications is proposed. Activity theory has been chosen as the conceptual framework for our formal model. The approach has been used for generating a first dataset containing pertinent daily activities to highlight the potential of the approach.