DocumentCode
705575
Title
Traffic Flow Classification and Visualization for Network Forensic Analysis
Author
Promrit, Nuttachot ; Mingkhwan, Anirach
Author_Institution
Fac. of Inf. Technol., King Mongkut´s Univ. of Technol. North Bangkok, Bangkok, Thailand
fYear
2015
fDate
24-27 March 2015
Firstpage
358
Lastpage
364
Abstract
This paper presents an iterative visualization technique including the timeline and parallel coordinates to illustrate network communication for forensic analysis. In primarily analysis process, the timeline of events is reconstructed from traffic logs. An analyst can track the related anomaly event on-demand. In addition the details of abnormal and normal activities are shown in multiple dimensions of parallel coordinates. The novelty of this research is not a presentation of the timeline and parallel coordinates technique, but iterative visualization framework to illustrate both anomaly traffic and application traffic pattern. We applied frequent item-set mining to search dominant traffic flow and classify them by traffic flow shape and entropy. Although some studies have been applied frequent item-set mining with traffic dataset, but as we have known, this is the first research to 1) take advantages of the frequent item-set mining and parallel coordinates, which allow us to find both the anomaly traffic and application traffic and it can easily understand the patterns of traffic flow with the multi-dimensional visualization, and 2) classify the application traffic from the entropy values of traffic flow discovered by frequent item-set mining. This method is able to classify the encrypted traffic data and it does not violate a user privacy. The results of this research and development of a visual network communication tool can: 1) show abnormalities and normal communication activities, 2) have application traffic classification 92% accurate, 3) be a visual network communication prototype which helps an analyst to find the cause of the network malfunction.
Keywords
telecommunication traffic; Internet; encrypted traffic data; entropy values; frequent item-set mining; item-set mining; iterative visualization technique; multidimensional visualization; network communication; network forensic analysis; network malfunction; parallel coordinates technique; research and development; timeline coordinates technique; traffic classification; traffic flow; traffic flow classification; traffic flow visualization; visual network communication; visualization framework; Data visualization; Entropy; Feature extraction; IP networks; Ports (Computers); Shape; Telecommunication traffic; Behavior Analysis; Entropy; Traffic Flow Classification; Traffic Flow Extraction;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications (AINA), 2015 IEEE 29th International Conference on
Conference_Location
Gwangiu
ISSN
1550-445X
Print_ISBN
978-1-4799-7904-2
Type
conf
DOI
10.1109/AINA.2015.207
Filename
7097992
Link To Document