Role Classification of Hosts within Enterprise Networks Based on Connection Patterns
Moscow Institute of Thermal Technology
Abstract
Role classification involves grouping hosts into related roles. It exposes the logical structure of a network, simplifies network management tasks such as policy checking and network segmentation, and can be used to improve the accuracy of network monitoring and analysis algorithms such as intrusion detection. This paper defines the role classification problem and introduces two practical algorithms that group hosts based on observed connection patterns while dealing with changes in these patterns over time. The algorithms have been implemented in a commercial network monitoring and analysis product for enterprise networks. Results from grouping two enterprise networks show that the number of groups identified…
Citation impact
- FWCI
- —
- Percentile
- —
- References
- 20
Authors
4Topics & keywords
- Computer science
- Intrusion detection system
- Enterprise private network
- Connection (principal bundle)
- Data mining
- Distributed computing
- Artificial intelligence
- Computer network