Dynamic Cluster Analysis to Detect and Track Novelty in Network Telescopes
Abstract: In the context of cybersecurity, tracking the activities of coordinated hosts over time is a daunting task because both participants and their behaviours evolve at a fast pace. We address this scenario by solving a dynamic novelty discovery problem with the aim of both re-identifying patterns seen in the past and highlighting new patterns. We focus on traffic collected by Network Telescopes, a primary and noisy source for cybersecurity analysis. We propose a 3-stage pipeline: (i) we learn compact representations (embeddings) of hosts through their traffic in a self-supervised fashion; (ii) via clustering, we distinguish groups of hosts performing similar activities; (iii) we track the cluster temporal evolution to highlight novel patterns. We apply our methodology to 20 days of telescope traffic during which we observe more than 8 thousand active hosts. Our results show that we efficiently identify 50-70 well-shaped clusters per day, 60-70% of which we associate with already analysed cases, while we pinpoint 10-20 previously unseen clusters per day. These correspond to activity changes and new incidents, of which we document some. In short, our novelty discovery methodology enormously simplifies the manual analysis the security analysts have to conduct to gain insights to interpret novel coordinated activities.
- Censys, 2021. https://censys.io/.
- The shadowserver foundation, 2021. https://www.shadowserver.org/.
- Mimetic: Mobile encrypted traffic classification using multimodal deep learning. Computer Networks, 2019.
- The evolution of mirai botnet scans over a six-year period. Journal of Information Security and Applications, 2023.
- Understanding the mirai botnet. In 26th USENIX security symposium (USENIX Security 17), 2017.
- Threat intelligence generation using network telescope data for industrial control systems. IEEE Transactions on Information Forensics and Security, 2021.
- Improving iot botnet investigation using an adaptive network layer. Sensors, 2019.
- DANTE: A framework for mining and monitoring darknet traffic. 2020.
- Ori David. Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal, 2024. Akamai.
- A density-based algorithm for discovering clusters in large spatial databases with noise. In kdd, 1996.
- Inferring Distributed Reflection Denial of Service Attacks from Darknet. Computer Communications, 2015.
- C. Fachkha and M. Debbabi. Darknet as a Source of Cyber Intelligence: Survey, Taxonomy, and Characterization. Commun. Surveys Tuts., 2016.
- Exploring temporal gnn embeddings for darknet traffic analysis. In Proceedings of the 2nd on Graph Neural Networking Workshop 2023, 2023.
- DarkVec: Automatic analysis of darknet traffic with word embeddings. In Proceedings of the 17th International Conference on emerging Networking EXperiments and Technologies, 2021.
- i-DarkVec: Incremental Embeddings for Darknet Traffic Analysis. ACM Transactions on Internet Technology, 2023.
- Ophir Harpaz. FritzFrog: A New Generation of Peer-to-Peer Botnets, 2022. Akamai.
- Towards a systematic multi-modal representation learning for network data. In Proceedings of the 21st ACM Workshop on Hot Topics in Networks, 2022.
- Unsupervised traffic flow classification using a neural autoencoder. In 2017 IEEE 42nd Conference on Local Computer Networks (LCN), 2017.
- Pattern discovery in internet background radiation. IEEE Transactions on Big Data, 5(4):467–480, 2017.
- Millions of Targets UnderAttack: A Macroscopic Characterization of the DoS Ecosystem. In Proceedings of the ACM SIGCOMM Internet Measurement Conference, 2017.
- Detecting and interpreting changes in scanning behavior in large network telescopes. IEEE Transactions on Information Forensics and Security, 2022.
- A comprehensive study of DDoS attacks over IoT network and their countermeasures. Computers & Security, 2023.
- Skdstream: a dynamic clustering algorithm on time-decaying data stream. EURASIP Journal on Wireless Communications and Networking, 2022.
- Graph self-supervised learning: A survey. IEEE Transactions on Knowledge and Data Engineering, 2022.
- Deep packet: A novel approach for encrypted traffic classification using deep learning, 2017.
- Scalable clustering algorithms for big data: A review. IEEE Access, 2021.
- Evolving clustering algorithm based on mixture of typicalities for stream data mining. Future Generation Computer Systems, 2020.
- HDBSCAN: Hierarchical Density Based Clustering. The Journal of Open Source Software, 2017.
- Efficient estimation of word representations in vector space. arXiv, 2013.
- n.a. Stupidly simple ddos protocol (ssdp) generates 100 gbps ddos, 2017. Cloudflare,https://blog.cloudflare.com/ssdp-100gbps/.
- n.a. Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs, NVRs and IP cameras, 2020. Habr.
- n.a. Mirai Botnet’s New Wave: hailBot,kiraiBot, catDDoS, and Their Fierce Onslaught, 2023. NSFOCUS.
- n.a. New Mirai-based Botnet Variants Emerge, 2023. SOCRadar.
- n.a. Qakbot Malware Disrupted in International Cyber Takedown, 2023. Office of Public Affairs – U.S. Department of Justice.
- The Hidden Enemy: A Botnet Taxonomy. In Proceedings of the International Conference on Paradigms of Computing, Communication and Data Sciences: PCCDS 2022, 2023.
- S. Rezaei and X. Liu. How to achieve high classification accuracy with just a few labels: A semi-supervised approach using sampled packets, 2018.
- IP2Vec: Learning Similarities Between IP Addresses. In 2017 IEEE International Conference on Data Mining Workshops (ICDMW), 2017.
- Introduction to information retrieval, volume 39. Cambridge University Press Cambridge, 2008.
- Sensing the noise: Uncovering communities in darknet traffic. In 2020 Mediterranean Communication and Computer Networking Conference (MedComNet), pages 1–8. IEEE, 2020.
- MONIC and Followups on Modeling and Monitoring Cluster Transitions. In Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2013, Prague, Czech Republic, September 23-27, 2013, Proceedings, Part III 13, 2013.
- Monic: modeling and monitoring cluster transitions. In Proceedings of the 12th ACM SIGKDD international conference on Knowledge discovery and data mining, pages 706–711, 2006.
- Cyber threat intelligence mining for proactive cybersecurity defense: A survey and new perspectives. IEEE Communications Surveys & Tutorials, 2023.
- Exploring Topic Models to Discern Cyber Threats on Twitter: A Case Study on Log4Shell. Intelligent Systems with Applications, 2023.
Paper Prompts
Sign up for free to create and run prompts on this paper using GPT-5.
Top Community Prompts
Collections
Sign up for free to add this paper to one or more collections.