In recent years, data-driven approaches have attracted the interest of the research community. Considering network monitoring, unsupervised machine learning solutions such as clustering are particularly appealing to let the network analysts observe patterns, and track the evolution of traffic over time. In this paper, we present a novel unsupervised methodology to automatically process and analyze batches of HTTP traffic, looking just at the URL structure. First, we describe IDBSCAN, Iterative-DBSCAN. We design it to obtain well-shaped clusters, and to simplify the choice of parameters — often a cumbersome step for the network analyst. Second, we show LENTA, Longitudinal Exploration for Network Traffic Analysis, which allows to automatically observe the evolution over time of traffic, naturally highlighting trends and pinpointing anomalies. We first evaluate IDBSCAN and LENTA on synthetic data to compare their performance against well-known algorithms. Then we apply them on a real case, facing the analysis of hundred thousands of URLs collected from a live network. Results show both the goodness of clusters produced by IDBSCAN and LENTA ability to highlight changes in traffic, facilitating the analyst job.
|Titolo:||Clustering and evolutionary approach for longitudinal web traffic analysis|
|Data di pubblicazione:||2019|
|Digital Object Identifier (DOI):||10.1016/j.peva.2019.102033|
|Appare nelle tipologie:||1.1 Articolo in rivista|
File in questo prodotto:
|1-s2.0-S0166531619300331-main.pdf||Versione finale||2a. Post-print Versione editoriale||Non Pubblico - Accesso privato/ristretto||Administrator Richiedi una copia|
|2019_LENTA_PEVA.pdf||Preprint del camera ready||2. Post-print||Embargo: 30/08/2021 Richiedi una copia|