Port2dist

Semantic port distances for network analytics

Laurent Evrard, Jerome Francois, Jean Noel Colin, Frederic Beck

Research output: Contribution in Book/Catalog/Report/Conference proceedingConference contribution

Abstract

Traffic analysis is a predominant task to support multiple types of management operations. When shifting from manually built signatures to machine learning techniques, a problem resides in the model to represent traffic features. The most notable examples are the TCP and UDP ports, near port numbers in the numerical space is not representative of a close semantic from an operational point of view. We have thus developed a technique to learn meaningful metrics between ports from scanning strategies followed by attackers. In this demonstration, we propose the port2dist tool, allowing to get, seek and retrieve semantic dissimilarities between port numbers.

Original languageEnglish
Title of host publication2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages747-748
Number of pages2
ISBN (Electronic)9783903176157
Publication statusPublished - 16 May 2019
Event2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019 - Arlington, United States
Duration: 8 Apr 201912 Apr 2019

Publication series

Name2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019

Conference

Conference2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019
CountryUnited States
CityArlington
Period8/04/1912/04/19

Fingerprint

Semantics
Learning systems
Demonstrations
Scanning

Cite this

Evrard, L., Francois, J., Colin, J. N., & Beck, F. (2019). Port2dist: Semantic port distances for network analytics. In 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019 (pp. 747-748). [8717840] (2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019). Institute of Electrical and Electronics Engineers Inc..
Evrard, Laurent ; Francois, Jerome ; Colin, Jean Noel ; Beck, Frederic. / Port2dist : Semantic port distances for network analytics. 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019. Institute of Electrical and Electronics Engineers Inc., 2019. pp. 747-748 (2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019).
@inproceedings{be785558cd7c48fcb3f3594967c38850,
title = "Port2dist: Semantic port distances for network analytics",
abstract = "Traffic analysis is a predominant task to support multiple types of management operations. When shifting from manually built signatures to machine learning techniques, a problem resides in the model to represent traffic features. The most notable examples are the TCP and UDP ports, near port numbers in the numerical space is not representative of a close semantic from an operational point of view. We have thus developed a technique to learn meaningful metrics between ports from scanning strategies followed by attackers. In this demonstration, we propose the port2dist tool, allowing to get, seek and retrieve semantic dissimilarities between port numbers.",
author = "Laurent Evrard and Jerome Francois and Colin, {Jean Noel} and Frederic Beck",
year = "2019",
month = "5",
day = "16",
language = "English",
series = "2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
pages = "747--748",
booktitle = "2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019",

}

Evrard, L, Francois, J, Colin, JN & Beck, F 2019, Port2dist: Semantic port distances for network analytics. in 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019., 8717840, 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019, Institute of Electrical and Electronics Engineers Inc., pp. 747-748, 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019, Arlington, United States, 8/04/19.

Port2dist : Semantic port distances for network analytics. / Evrard, Laurent; Francois, Jerome; Colin, Jean Noel; Beck, Frederic.

2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019. Institute of Electrical and Electronics Engineers Inc., 2019. p. 747-748 8717840 (2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019).

Research output: Contribution in Book/Catalog/Report/Conference proceedingConference contribution

TY - GEN

T1 - Port2dist

T2 - Semantic port distances for network analytics

AU - Evrard, Laurent

AU - Francois, Jerome

AU - Colin, Jean Noel

AU - Beck, Frederic

PY - 2019/5/16

Y1 - 2019/5/16

N2 - Traffic analysis is a predominant task to support multiple types of management operations. When shifting from manually built signatures to machine learning techniques, a problem resides in the model to represent traffic features. The most notable examples are the TCP and UDP ports, near port numbers in the numerical space is not representative of a close semantic from an operational point of view. We have thus developed a technique to learn meaningful metrics between ports from scanning strategies followed by attackers. In this demonstration, we propose the port2dist tool, allowing to get, seek and retrieve semantic dissimilarities between port numbers.

AB - Traffic analysis is a predominant task to support multiple types of management operations. When shifting from manually built signatures to machine learning techniques, a problem resides in the model to represent traffic features. The most notable examples are the TCP and UDP ports, near port numbers in the numerical space is not representative of a close semantic from an operational point of view. We have thus developed a technique to learn meaningful metrics between ports from scanning strategies followed by attackers. In this demonstration, we propose the port2dist tool, allowing to get, seek and retrieve semantic dissimilarities between port numbers.

UR - http://www.scopus.com/inward/record.url?scp=85067062211&partnerID=8YFLogxK

M3 - Conference contribution

T3 - 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019

SP - 747

EP - 748

BT - 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019

PB - Institute of Electrical and Electronics Engineers Inc.

ER -

Evrard L, Francois J, Colin JN, Beck F. Port2dist: Semantic port distances for network analytics. In 2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019. Institute of Electrical and Electronics Engineers Inc. 2019. p. 747-748. 8717840. (2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019).