Statistical Modelling of Computer Network Traffic Event Times

11/28/2017
by   Matthew Price-Williams, et al.
0

This paper introduces a statistical model for the arrival times of connection events in a computer network. Edges between nodes in a network can be interpreted and modelled as point processes where events in the process indicate information being sent along that edge. A model of normal behaviour can be constructed for each edge in the network by identifying key network user features such as seasonality and self-exciting behaviour, where events typically arise in bursts at particular times of day. When monitoring the network in real time, unusual patterns of activity could indicate the presence of a malicious actor. Four different models for self-exciting behaviour are introduced and compared using data collected from the Imperial College and Los Alamos National Laboratory computer networks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/19/2017

Sonification of Network Traffic Flow for Monitoring and Situational Awareness

Maintaining situational awareness of what is happening within a network ...
research
03/20/2019

Algorithms of evaluation of the waiting time and the modelling of the terminal activity

This paper approaches the application of the waiting model with Poisson ...
research
09/20/2022

Peer-group Behaviour Analytics of Windows Authentications Events Using Hierarchical Bayesian Modelling

Cyber-security analysts face an increasingly large number of alerts rece...
research
02/11/2021

Mutually exciting point process graphs for modelling dynamic networks

A new class of models for dynamic networks is proposed, called mutually ...
research
10/27/2017

Identifying overlapping terrorist cells from the Noordin Top actor-event network

Actor-event data are common in sociological settings, whereby one regist...
research
05/19/2022

Recurrent segmentation meets block models in temporal networks

A popular approach to model interactions is to represent them as a netwo...
research
11/08/2017

RCNF: Real-time Collaborative Network Forensic Scheme for Evidence Analysis

Network forensic techniques help in tracking different types of cyber at...

Please sign up or login with your details

Forgot password? Click here to reset