Netinfo Security ›› 2018, Vol. 18 ›› Issue (12): 1-7.doi: 10.3969/j.issn.1671-1122.2018.12.001

    Next Articles

Host Behavior Analysis Based on Bipartite Graph Model

Jinsong WANG1,2,3(), Huirong NAN1,2,3, Honghao ZHANG1,2,3   

  1. 1. School of Computer Science and Engineering, Tianjin University of Technology, Tianjin 300384, China
    2. National Engineering Laboratory for Computer Virus Prevention and Control Technology, Tianjin 300457, China
    3. Tianjin Key Laboratory of Intelligence Computing and Novel Software Technology, Tianjin 300384, China
  • Received:2018-01-11 Online:2018-12-20 Published:2020-05-11

Abstract:

In recent years, with the continuous increase of the network scale, diversification of network applications and the gradual maturity of the encrypted data transmission technology, the analysis of the terminal host behavior have become more and more complicated. This paper presents a graph-based approach that uses community detection to discover end hosts with similar behavior. And the approach are scalable and practical by introducing Spark GraphX technology. The experimental results show that this method has strong validity and reference in the data analysis based on NetFlow, and can be referenced for large-scale network analysis.

Key words: graph model, NetFlow, distributed computing, network security, community detection

CLC Number: