- Title
- Correlation and comparative analysis of traffic across five network telescopes
- Creator
- Nkhumeleni, Thizwilondi Moses
- ThesisAdvisor
- Irwin, Barry Vivian William
- Subject
- Sensor networks
- Subject
- Computer networks
- Subject
- TCP/IP (Computer network protocol)
- Subject
- Computer networks -- Management
- Subject
- Electronic data processing -- Management
- Date
- 2014
- Type
- Thesis
- Type
- Masters
- Type
- MSc
- Identifier
- vital:4693
- Identifier
- http://hdl.handle.net/10962/d1011668
- Identifier
- Sensor networks
- Identifier
- Computer networks
- Identifier
- TCP/IP (Computer network protocol)
- Identifier
- Computer networks -- Management
- Identifier
- Electronic data processing -- Management
- Description
- Monitoring unused IP address space by using network telescopes provides a favourable environment for researchers to study and detect malware, worms, denial of service and scanning activities. Research in the field of network telescopes has progressed over the past decade resulting in the development of an increased number of overlapping datasets. Rhodes University's network of telescope sensors has continued to grow with additional network telescopes being brought online. At the time of writing, Rhodes University has a distributed network of five relatively small /24 network telescopes. With five network telescope sensors, this research focuses on comparative and correlation analysis of traffic activity across the network of telescope sensors. To aid summarisation and visualisation techniques, time series' representing time-based traffic activity, are constructed. By employing an iterative experimental process of captured traffic, two natural categories of the five network telescopes are presented. Using the cross- and auto-correlation methods of time series analysis, moderate correlation of traffic activity was achieved between telescope sensors in each category. Weak to moderate correlation was calculated when comparing category A and category B network telescopes' datasets. Results were significantly improved by studying TCP traffic separately. Moderate to strong correlation coefficients in each category were calculated when using TCP traffic only. UDP traffic analysis showed weaker correlation between sensors, however the uniformity of ICMP traffic showed correlation of traffic activity across all sensors. The results confirmed the visual observation of traffic relativity in telescope sensors within the same category and quantitatively analysed the correlation of network telescopes' traffic activity.
- Format
- 122 p., pdf
- Publisher
- Rhodes University, Faculty of Science, Computer Science
- Language
- English
- Rights
- Nkhumeleni, Thizwilondi Moses
- Hits: 1769
- Visitors: 1943
- Downloads: 230
Thumbnail | File | Description | Size | Format | |||
---|---|---|---|---|---|---|---|
View Details | SOURCEPDF | 939 KB | Adobe Acrobat PDF | View Details |