METHOD AND SYSTEM FOR CLUSTERING DARKNET TRAFFIC STREAMS WITH WORD EMBEDDINGS

    公开(公告)号:EP3719685A1

    公开(公告)日:2020-10-07

    申请号:EP20167836.4

    申请日:2020-04-02

    IPC分类号: G06F21/57 H04L29/06

    摘要: A system for analyzing and clustering darknet traffic streams with word embeddings, comprising a data processing module which collects packets that are sent to non-existing IP addresses that belong to darknet's taps (blackholes) that are deployed over the internet; a port embedding module for performing port sequence embeddings by using a word embedding algorithm on the port sequences extracted from the data processing module while transforming the port sequences into a meaningful numerical feature vectors; a clustering module for performing temporal clustering of the feature vectors over time; and an alert logic and visualization module visualizes the data and provides alerts regarding a cluster that an analyst classified as malicious in the past.