A self-organizing map and its modeling for discovering malignant network traffic

Chet Langin, Hongbo Zhou, Shahram Rahimi, Bidyut Gupta, Mehdi R. Zargham, M.R. Sayeh

2009 · 25 citations · 23 references

Concepts

Abstract

Model-based intrusion detection and knowledge discovery are combined to cluster and classify P2P botnet traffic and other malignant network activity by using a self-organizing map (som) self-trained on denied Internet firewall log entries. The SOM analyzed new firewall log entries in a case study to classify similar network activity, and discovered previously unknown local P2P bot traffic and other security issues.

References

23