TY - GEN
T1 - Network-aware behavior clustering of Internet end hosts
AU - Xu, Kuai
AU - Wang, Feng
AU - Gu, Lin
PY - 2011/8/2
Y1 - 2011/8/2
N2 - This paper explores the behavior similarity of Internet end hosts in the same network prefixes. We use bipartite graphs to model network traffic, and then construct one-mode projection graphs for capturing social-behavior similarity of end hosts. By applying a simple and efficient spectral clustering algorithm, we perform network-aware clustering of end hosts in the same prefixes into different behavior clusters. Based on information-theoretical measures, we find that the clusters exhibit distinct traffic characteristics which provides improved interpretations of the separated traffic compared with the aggregated traffic of the prefixes. Finally, we demonstrate the applications of exploring behavior similarity in profiling network behaviors and detecting anomalous behaviors through synthetic traffic that combines Internet backbone traffic and packet traces from real scenarios of worm propagations and denial of service attacks.
AB - This paper explores the behavior similarity of Internet end hosts in the same network prefixes. We use bipartite graphs to model network traffic, and then construct one-mode projection graphs for capturing social-behavior similarity of end hosts. By applying a simple and efficient spectral clustering algorithm, we perform network-aware clustering of end hosts in the same prefixes into different behavior clusters. Based on information-theoretical measures, we find that the clusters exhibit distinct traffic characteristics which provides improved interpretations of the separated traffic compared with the aggregated traffic of the prefixes. Finally, we demonstrate the applications of exploring behavior similarity in profiling network behaviors and detecting anomalous behaviors through synthetic traffic that combines Internet backbone traffic and packet traces from real scenarios of worm propagations and denial of service attacks.
UR - http://www.scopus.com/inward/record.url?scp=79960853919&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=79960853919&partnerID=8YFLogxK
U2 - 10.1109/INFCOM.2011.5935017
DO - 10.1109/INFCOM.2011.5935017
M3 - Conference contribution
AN - SCOPUS:79960853919
SN - 9781424499212
T3 - Proceedings - IEEE INFOCOM
SP - 2078
EP - 2086
BT - 2011 Proceedings IEEE INFOCOM
T2 - IEEE INFOCOM 2011
Y2 - 10 April 2011 through 15 April 2011
ER -