Correlation and comparative analysis of traffic across five network telescopes

dc.contributor.advisorIrwin, Barry Vivian William
dc.contributor.authorNkhumeleni, Thizwilondi Moses
dc.date.accessioned2026-03-04T08:21:59Z
dc.date.issued2014
dc.description.abstractMonitoring unused IP address space by using network telescopes provides a favourable environment for researchers to study and detect malware, worms, denial of service and scanning activities. Research in the field of network telescopes has progressed over the past decade resulting in the development of an increased number of overlapping datasets. Rhodes University's network of telescope sensors has continued to grow with additional network telescopes being brought online. At the time of writing, Rhodes University has a distributed network of five relatively small /24 network telescopes. With five network telescope sensors, this research focuses on comparative and correlation analysis of traffic activity across the network of telescope sensors. To aid summarisation and visualisation techniques, time series' representing time-based traffic activity, are constructed. By employing an iterative experimental process of captured traffic, two natural categories of the five network telescopes are presented. Using the cross- and auto-correlation methods of time series analysis, moderate correlation of traffic activity was achieved between telescope sensors in each category. Weak to moderate correlation was calculated when comparing category A and category B network telescopes' datasets. Results were significantly improved by studying TCP traffic separately. Moderate to strong correlation coefficients in each category were calculated when using TCP traffic only. UDP traffic analysis showed weaker correlation between sensors, however the uniformity of ICMP traffic showed correlation of traffic activity across all sensors. The results confirmed the visual observation of traffic relativity in telescope sensors within the same category and quantitatively analysed the correlation of network telescopes' traffic activity.
dc.description.degreeMaster's thesis
dc.description.degreeMSc
dc.format.extent122 pages
dc.format.mimetypeapplication/pdf
dc.identifier.otherhttp://hdl.handle.net/10962/d1011668
dc.identifier.urihttps://researchrepository.ru.ac.za/handle/123456789/5797
dc.languageEnglish
dc.publisherRhodes University, Faculty of Science, Department of Computer Science
dc.rightsNkhumeleni, Thizwilondi Moses
dc.subjectSensor networks
dc.subjectComputer networks
dc.subjectTCP/IP (Computer network protocol)
dc.subjectComputer networks -- Management
dc.subjectElectronic data processing -- Management
dc.titleCorrelation and comparative analysis of traffic across five network telescopes
dc.typeAcademic thesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Correlation_and_comparative_analysis_of_traffic_ac_vital_4693.pdf
Size:
939.1 KB
Format:
Adobe Portable Document Format