Distributed, Multi-Level Network Anomaly Detection for Datacentre Networks

被引:0
|
作者
Iordache, Mircea [1 ]
Jouet, Simon [1 ]
Marnerides, Angelos K. [2 ]
Pezaros, Dimitrios P. [1 ]
机构
[1] Univ Glasgow, Sch Comp Sci, Glasgow G12 8QQ, Lanark, Scotland
[2] Univ Lancaster, Sch Comp & Commun, InfoLab21, Lancaster LA1 4WA, England
基金
英国工程与自然科学研究理事会;
关键词
BACKBONE NETWORKS;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Over the past decade, numerous systems have been proposed to detect and subsequently prevent or mitigate security vulnerabilities. However, many existing intrusion or anomaly detection solutions are limited to a subset of the traffic due to scalability issues, hence failing to operate at line-rate on large, highspeed datacentre networks. In this paper, we present a two-level solution for anomaly detection leveraging independent execution and message passing semantics. We employ these constructs within a network-wide distributed anomaly detection framework that allows for greater detection accuracy and bandwidth cost saving through attack path reconstruction. Experimental results using real operational traffic traces and known network attacks generated through the Pytbull IDS evaluation framework, show that our approach is capable of detecting anomalies in a timely manner while allowing reconstruction of the attack path, hence further enabling the composition of advanced mitigation strategies. The resulting system shows high detection accuracy when compared to similar techniques, at least 20% better at detecting anomalies, and enables full path reconstruction even at smallto- moderate attack traffic intensities (as a fraction of the total traffic), saving up to 75% of bandwidth due to early attack detection.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] A distributed multi-level anomalies detection system using the mobile agent approach
    Ben Ftima, Fakher
    Tounsi, Wiem
    Karoui, Kamel
    Ben Ghezala, Henda
    [J]. 2009 GLOBAL INFORMATION INFRASTRUCTURE SYMPOSIUM (GIIS 2009), 2009, : 326 - +
  • [42] Military object detection in defense using multi-level capsule networks
    B. Janakiramaiah
    G. Kalyani
    A. Karuna
    L. V. Narasimha Prasad
    M. Krishna
    [J]. Soft Computing, 2023, 27 : 1045 - 1059
  • [43] CEIFA: A multi-level anomaly detector for smart farming
    Zanella, Angelita Rettore de Araujo
    da Silva, Eduardo
    Albini, Luiz Carlos Pessoa
    [J]. COMPUTERS AND ELECTRONICS IN AGRICULTURE, 2022, 202
  • [44] MapsNet: Multi-level feature constraint and fusion network for change detection
    Pan, Jianping
    Cui, Wei
    An, Xinyong
    Huang, Xiao
    Zhang, Hanchao
    Zhang, Sihang
    Zhang, Ruiqian
    Li, Xin
    Cheng, Weihua
    Hu, Yong
    [J]. INTERNATIONAL JOURNAL OF APPLIED EARTH OBSERVATION AND GEOINFORMATION, 2022, 108
  • [45] Multi-level Gaussian mixture modeling for detection of malicious network traffic
    Chapaneri, Radhika
    Shah, Seema
    [J]. JOURNAL OF SUPERCOMPUTING, 2021, 77 (05): : 4618 - 4638
  • [46] Optimal network intrusion detection assignment in multi-level IoT systems
    Dao, Thi-Nga
    Van Le, Duc
    Tran, Xuan Nam
    [J]. COMPUTER NETWORKS, 2023, 232
  • [47] Attention Guided Multi-level Feedback Network for Camouflage Object Detection
    Tang, Qiuyan
    Ye, Jialin
    Chen, Fukang
    Yuan, Xia
    [J]. PATTERN RECOGNITION, ACPR 2021, PT I, 2022, 13188 : 226 - 239
  • [48] Sarcasm Detection with Sentiment Semantics Enhanced Multi-level Memory Network
    Ren, Lu
    Xu, Bo
    Lin, Hongfei
    Liu, Xikai
    Yang, Liang
    [J]. NEUROCOMPUTING, 2020, 401 : 320 - 326
  • [49] Multi-level refinement enriched feature pyramid network for object detection
    Aziz, Lubna
    FC, Md. Sah Bin Haji Salam
    Ayub, Sara
    [J]. Image and Vision Computing, 2021, 115
  • [50] Multi-Level Attention Interactive Network for Cloud and Snow Detection Segmentation
    Ding, Li
    Xia, Min
    Lin, Haifeng
    Hu, Kai
    [J]. REMOTE SENSING, 2024, 16 (01)