主催: 電気・情報関係学会九州支部連合大会委員会
会議名: 平成30年度電気・情報関係学会九州支部連合大会
回次: 71
開催地: 大分大学
開催日: 2018/09/27 - 2018/09/28
Darknet traffic volume is increasing year by year. And, it is hard to detect the malicious activities from many network traffic. Therefore, we try to classify based on the characteristics of the source hosts. We extracted each parameter from the packet headers and aggregated per source host for clustering. Output clusters include source hosts with the same features. We verified the clustered the traffic for TCP/4786 collected on our university’s darknet traffic. As a result, we succeeded in classifying the distributed scan activity for each organization.