A Taxonomy of Anomalies in Backbone Network Traffic

被引:0
|
作者
Mazel, Johan
Fontugne, Romain
Fukuda, Kensuke
机构
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The potential threat of network anomalies on Internet has led to a constant effort by the research community to design reliable detection methods. Detection is not enough, however, because network administrators need additional information on the nature of events occurring in a network. Several works try to classify detected events or establish a taxonomy of known events. But, these works are non-overlapping in terms of anomaly type coverage. On the one hand, existing classification methods use a limited set of labels. On the other hand, taxonomies often target a single type of anomaly or, when they have wider scope, fail to present the full spectrum of what really happens in the wild. We thus present a new taxonomy of network anomalies with wide coverage of existing work. We also provide a set of signatures that assign taxonomy labels to events. We present a preliminary study applying this taxonomy with six years of real network traffic from the MAWI repository. We classify previously documented anomalous events and draw to main conclusions. First, the taxonomy-based analysis provides new insights regarding events previous classified by heuristic rule labeling. For example, some RST events are now classified as network scan response and the majority of ICMP events are split into network scans and network scan responses. Moreover, some previously unknown events now account for a substantial number of all UDP network scans, network scan responses and port scans. Second, the number of unknown events decreases from 20 to 10% of all events with the proposed taxonomy as compared to the heuristic approach.
引用
收藏
页码:30 / 36
页数:7
相关论文
共 50 条
  • [1] Detecting and tracing traffic volume anomalies in SINET3 backbone network
    Du, Ping
    Abe, Shunji
    Ji, Yusheng
    Sato, Seishou
    Ishiguro, Makio
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, PROCEEDINGS, VOLS 1-13, 2008, : 5833 - +
  • [2] Anomalies in Network Traffic
    Ratner, Alan S.
    Kelly, Phillip
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS: BIG DATA, EMERGENT THREATS, AND DECISION-MAKING IN SECURITY INFORMATICS, 2013, : 206 - 208
  • [3] Detecting Network Anomalies in Backbone Networks
    Callegari, Christian
    Gazzarrini, Loris
    Giordano, Stefano
    Pagano, Michele
    Pepe, Teresa
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, 2010, 6307 : 490 - 491
  • [4] Analysis of Internet Backbone Traffic and Header Anomalies Observed
    John, Wolfgang
    Tafvelin, Sven
    [J]. IMC'07: PROCEEDINGS OF THE 2007 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE, 2007, : 111 - 116
  • [5] Detecting anomalies in backbone network traffic: a performance comparison among several change detection methods
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    Pepe, Teresa
    [J]. INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2012, 11 (04) : 205 - 214
  • [6] Global Modeling of Backbone Network Traffic
    Stoev, Stilian
    Michailidis, George
    Vaughan, Joel
    [J]. 2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [7] City Backbone Network Traffic Forecasting
    Serikov, Tansaule
    Zhetpisbayeva, Ainur
    Akhmediyarova, Ainur
    Mirzakulova, Sharafat
    Kismanova, Aigerim
    Tologenova, Aray
    Wojcik, Waldemar
    [J]. INTERNATIONAL JOURNAL OF ELECTRONICS AND TELECOMMUNICATIONS, 2021, 67 (03) : 319 - 324
  • [8] Neural Network Model to Group Traffic in Backbone Network
    Moungnoul, Phichet
    Panitjaroen, Natthawut
    Sato, Tomoaki
    [J]. 2ND INTERNATIONAL SCIENCE, SOCIAL SCIENCE, ENGINEERING AND ENERGY CONFERENCE 2010 (I-SEEC 2010), 2011, 8 : 47 - 52
  • [9] Research on Mobile Network Traffic Taxonomy
    Liu, Zhen
    Wang, Ruoyu
    Tang, Deyu
    [J]. 2016 INTERNATIONAL CONFERENCE ON COMPUTER, INFORMATION AND TELECOMMUNICATION SYSTEMS (CITS), 2016, : 309 - 313
  • [10] A structured approach to network backbone traffic estimation
    Ciglaric, M
    Vidmar, T
    [J]. PARALLEL AND DISTRIBUTED COMPUTING SYSTEMS - PROCEEDINGS OF THE ISCA 9TH INTERNATIONAL CONFERENCE, VOLS I AND II, 1996, : 286 - 291