MapReduce approach to build network user profiles with top-k rankings for network security

Resumen

Network-user profiling has been used as security technique to detect unknown or malicious behaviors. Top-k rankings of reached services is a new technique for building user profiles. This technique requires to keep in memory all the traffic data during a period of time to build the rankings. However, a single user can produce gigabytes of network traffic data, which may result in low execution performance and out-of-memory errors. This work proposes a MapReduce approach that generates top-k rankings from huge network capture files.

Descripción

Palabras clave

network security, Cybersecurity, Top-k Ranking, Map Reduce, Internal Network Security

Citación

Parres-Peredo, A.I.; Piza-Davila, H.I.and Cervantes, F. Map-reduce approach to build network user profiles with top-k rankings, Internal Report PhDEngScITESO-17-54-R, ITESO, Tlaquepaque, Mexico, Dec. 2017.