Using AI/ML to gain situational understanding from passive network observations

10/14/2019
by   D. Verma, et al.
0

The data available in the network traffic fromany Government building contains a significant amount ofinformation. An analysis of the traffic can yield insightsand situational understanding about what is happening inthe building. However, the use of traditional network packet inspection, either deep or shallow, is useful for only a limited understanding of the environment, with applicability limited to some aspects of network and security management. If weuse AI/ML based techniques to understand the network traffic, we can gain significant insights which increase our situational awareness of what is happening in the environment.At IBM, we have created a system which uses a combination of network domain knowledge and machine learning techniques to convert network traffic into actionable insights about the on premise environment. These insights include characterization of the communicating devices, discovering unauthorized devices that may violate policy requirements, identifying hidden components and vulnerability points, detecting leakage of sensitive information, and identifying the presence of people and devices.In this paper, we will describe the overall design of this system, the major use-cases that have been identified for it, and the lessons learnt when deploying this system for some of those use-cases

READ FULL TEXT
research
10/22/2018

Challenges in Network Management of Encrypted Traffic

This paper summarizes the challenges identified at the MAMI Management a...
research
09/15/2023

A Testbed for Automating and Analysing Mobile Devices and their Applications

The need for improved network situational awareness has been highlighted...
research
12/21/2022

The Internet of Senses: Building on Semantic Communications and Edge Intelligence

The Internet of Senses (IoS) holds the promise of flawless telepresence-...
research
09/02/2022

Waiting for QUIC: On the Opportunities of Passive Measurements to Understand QUIC Deployments

In this paper, we study the potentials of passive measurements to gain a...
research
04/11/2023

TinyReptile: TinyML with Federated Meta-Learning

Tiny machine learning (TinyML) is a rapidly growing field aiming to demo...
research
06/19/2022

Prevent Car Accidents by Using AI

Transportation facilities are becoming more developed as society develop...
research
04/08/2019

Efficient Passive ICS Device Discovery and Identification by MAC Address Correlation

Owing to a growing number of attacks, the assessment of Industrial Contr...

Please sign up or login with your details

Forgot password? Click here to reset