The expansion of computer networks has lead to the increase of online network attacks. Therefore, an efficient method to detect and analyze network attacks is inevitable. As a result much research has been done on network visualization. This paper proposes a method which efficiently visualizes and analyzes network attacks using parallel coordinates. A brief review on the limitations on previous visualization methods and a structure which can analyze network attacks through visualization will be presented. Moreover, experimental results on visualization of scanning attacks, denial of service attacks and spoofing attacks using multi parallel coordinates will be shown.
Recent botnets are widely using the DNS services at the connection of C&C server in order to evade botnet's detection. It is necessary to study on DNS analysis in order to counteract anomaly-based technique using the DNS. This paper studies collection of DNS traffic for experimental data and supervised learning for DNS traffic-based malicious domain classification such as query of domain name corresponding to C&C server from zombies. Especially, this paper would aim to determine significant features of DNS-based classification system for malicious domain extraction by the Principal Component Analysis(PCA).
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.