Distributed, Multi-Level Network Anomaly Detection for Datacentre Networks

被引:0
|
作者
Iordache, Mircea [1 ]
Jouet, Simon [1 ]
Marnerides, Angelos K. [2 ]
Pezaros, Dimitrios P. [1 ]
机构
[1] Univ Glasgow, Sch Comp Sci, Glasgow G12 8QQ, Lanark, Scotland
[2] Univ Lancaster, Sch Comp & Commun, InfoLab21, Lancaster LA1 4WA, England
基金
英国工程与自然科学研究理事会;
关键词
BACKBONE NETWORKS;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Over the past decade, numerous systems have been proposed to detect and subsequently prevent or mitigate security vulnerabilities. However, many existing intrusion or anomaly detection solutions are limited to a subset of the traffic due to scalability issues, hence failing to operate at line-rate on large, highspeed datacentre networks. In this paper, we present a two-level solution for anomaly detection leveraging independent execution and message passing semantics. We employ these constructs within a network-wide distributed anomaly detection framework that allows for greater detection accuracy and bandwidth cost saving through attack path reconstruction. Experimental results using real operational traffic traces and known network attacks generated through the Pytbull IDS evaluation framework, show that our approach is capable of detecting anomalies in a timely manner while allowing reconstruction of the attack path, hence further enabling the composition of advanced mitigation strategies. The resulting system shows high detection accuracy when compared to similar techniques, at least 20% better at detecting anomalies, and enables full path reconstruction even at smallto- moderate attack traffic intensities (as a fraction of the total traffic), saving up to 75% of bandwidth due to early attack detection.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Multi-level anomaly detection: Relevance of big data analytics in networks
    Sait, Saad Y.
    Bhandari, Akshay
    Khare, Shreya
    James, Cyriac
    Murthy, Hema A.
    [J]. SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2015, 40 (06): : 1737 - 1767
  • [2] Multi-level anomaly detection: Relevance of big data analytics in networks
    Sait S.
    Bhandari A.
    Khare S.
    James C.
    Murthy H.
    [J]. Sadhana, 2015, 40 (6) : 1737 - 1767
  • [3] The multi-level paradigm for distributed fault detection in networks with unreliable processors
    Thulasiraman, K
    Su, MS
    Goel, V
    [J]. PROCEEDINGS OF THE 2003 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOL III: GENERAL & NONLINEAR CIRCUITS AND SYSTEMS, 2003, : 862 - 865
  • [4] EDMAND: Edge-Based Multi-Level Anomaly Detection for SCADA Networks
    Ren, Wenyu
    Yardley, Timothy
    Nahrstedt, Klara
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CONTROL, AND COMPUTING TECHNOLOGIES FOR SMART GRIDS (SMARTGRIDCOMM), 2018,
  • [5] Multi-level framework for anomaly detection in social networking
    Khamparia, Aditya
    Pande, Sagar
    Gupta, Deepak
    Khanna, Ashish
    Sangaiah, Arun Kumar
    [J]. LIBRARY HI TECH, 2020, 38 (02) : 350 - 366
  • [6] Multi-level reasoning for managing distributed enterprises and their networks
    Frey, J
    Lewis, L
    [J]. INTEGRATED NETWORK MANAGEMENT V: INTEGRATED MANAGEMENT IN A VIRTUAL WORLD, 1997, : 5 - 16
  • [7] MFFA: Multi-level feature fusion and anomaly map compensation for anomaly detection
    Zhang, Ruifan
    Wang, Hao
    Yang, Gongping
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (05) : 7195 - 7210
  • [8] A Multi-Level Approach for Modelling Distributed Agent Network
    Makoond, Bippin
    Khaddaj, Souheil
    Oudrhiri, Radouane
    [J]. JOURNAL OF ALGORITHMS & COMPUTATIONAL TECHNOLOGY, 2010, 4 (03) : 311 - 323
  • [9] Multi-level Anomaly Detection in Industrial Control Systems via Package Signatures and LSTM networks
    Feng, Cheng
    Li, Tingting
    Chana, Deeph
    [J]. 2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2017, : 261 - 272
  • [10] Weakly supervised anomaly detection with multi-level contextual modeling
    Liu, Mengting
    Li, Xinrui
    Liu, Yongge
    Han, Yahong
    [J]. MULTIMEDIA SYSTEMS, 2023, 29 (04) : 2153 - 2164