L. B. Shyamasundar, V. A. Kumar, Jhansi Rani Prathuri
{"title":"Analyzing Big Data Originated from Data Communication Networks using K-Means Algorithm to Understand the Nature of Incoming Malicious Connections","authors":"L. B. Shyamasundar, V. A. Kumar, Jhansi Rani Prathuri","doi":"10.1109/MPCIT51588.2020.9350510","DOIUrl":null,"url":null,"abstract":"An environment is developed with a distributed Apache SPARK, deployed on Hadoop cluster for timely inference and classification of security incidents. Analysis of 85GB of network-packet dataset collected over four months is done (provided by CSIR-4PI, Govt. of India). K-means machine learning algorithm is used to analyze the network traffic based on various fields. By building and evaluating models, optimum number of clusters was determined. Clustering results are evaluated by calculating the clustering score using Within-Set Sum-of-Squared-Errors(WSSSE), entropy, Silhotte, Davies-Bouldin-Index and Dunn-Index. Several plots are visualized to understand the clustering analysis results and understand the nature of incoming malicious connections.","PeriodicalId":136514,"journal":{"name":"2020 Third International Conference on Multimedia Processing, Communication & Information Technology (MPCIT)","volume":"106 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 Third International Conference on Multimedia Processing, Communication & Information Technology (MPCIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MPCIT51588.2020.9350510","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
An environment is developed with a distributed Apache SPARK, deployed on Hadoop cluster for timely inference and classification of security incidents. Analysis of 85GB of network-packet dataset collected over four months is done (provided by CSIR-4PI, Govt. of India). K-means machine learning algorithm is used to analyze the network traffic based on various fields. By building and evaluating models, optimum number of clusters was determined. Clustering results are evaluated by calculating the clustering score using Within-Set Sum-of-Squared-Errors(WSSSE), entropy, Silhotte, Davies-Bouldin-Index and Dunn-Index. Several plots are visualized to understand the clustering analysis results and understand the nature of incoming malicious connections.