Anomaly Detection using Wavelet-Based Estimation of LRD in Packet and Byte Count of Control Traffic

被引:0
|
作者
Zeb, Khan [1 ,2 ]
AsSadhan, Basil [1 ,2 ]
Al-Muhtadi, Jalal [1 ,3 ]
Alshebeili, Saleh [2 ,4 ]
机构
[1] King Saud Univ, Ctr Excellence Informat Assurance CoEIA, Riyadh, Saudi Arabia
[2] King Saud Univ, Coll Engn, Dept Elect Engn, Riyadh, Saudi Arabia
[3] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Sci, Riyadh, Saudi Arabia
[4] King Saud Univ, KACST TIC RF & Photon E Soc RFTONICS, Riyadh, Saudi Arabia
关键词
anomaly detection; LRD; control traffic; network traffic analysis; wavelet;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The detection of anomalous behavior such as low volume attacks and abnormalities in today's large volume of Internet traffic has become a challenging problem in the network community. An efficient and real-time detection of anomaly traffic is crucial in order to rapidly diagnose and mitigate the anomaly, and to recover the resulting malfunction. In this paper, we present an efficient anomaly detection method based on the estimation of long-range dependence (LRD) behavior in packet and byte count of the aggregated control traffic. This method surrogates Internet aggregated whole traffic (i.e., control plus data) by the aggregated control traffic and detects anomaly traffic through the wavelet-based estimation of LRD behavior in the corresponding control traffic. Since Internet traffic exhibits LRD behavior during benign normal condition, deviation from this behavior can indicate an anomalous behavior. Experiments on the KSU dataset demonstrate that this method not only significantly improves the process of anomaly detection by considerably reducing the large-volume of traffic to be processed but also achieves a high detection effect. Because the control traffic constitute a small fraction of the whole traffic, and usually most of the attacks are manifested and carried out in the control traffic; therefore, surrogating the whole traffic by the control traffic increases the detection efficacy.
引用
收藏
页码:316 / 321
页数:6
相关论文
共 50 条
  • [1] Anomaly detection of network traffic based on wavelet packet
    Gao, Jun
    Hu, Guangmin
    Yao, Xingmiao
    Chang, Rocky K. C.
    2006 ASIA-PACIFIC CONFERENCE ON COMMUNICATION, VOLS 1 AND 2, 2006, : 660 - 664
  • [2] Anomaly Detection By Diffusion Wavelet-based Analysis on Traffic Matrix
    Sun, Teng
    Tian, Hui
    2014 SIXTH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND PROGRAMMING (PAAP), 2014, : 148 - 151
  • [3] Anomaly Detection and Localization by Diffusion Wavelet-based Analysis on Traffic Matrix
    Sun, Teng
    Tian, Hui
    Mei, Xuan
    COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2015, 12 (04) : 1361 - 1374
  • [4] RPCA and Wavelet packet Decomposition based Network Traffic Anomaly Detection
    Sythalakshmi, C. S.
    Arya, C., V
    Aswathy, G.
    Baburaj, M.
    2022 IEEE 19TH INDIA COUNCIL INTERNATIONAL CONFERENCE, INDICON, 2022,
  • [5] Volume Based Anomaly Detection using LRD Analysis of Decomposed Network Traffic
    Zeb, Khan
    AsSadhan, Basil
    Al-Muhtadi, Jalal
    Alshebeili, Saleh
    Bashaiwth, Abdulmuneem
    2014 FOURTH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING TECHNOLOGY (INTECH), 2014, : 52 - 57
  • [6] Wavelet-Based Anomaly Detection on Digital Signals
    Aydin, Omer
    Kurnaz, Melek
    2017 25TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2017,
  • [7] Anomaly Detection Based on LRD Behavior Analysis of Decomposed Control and Data Planes Network Traffic Using SOSS and FARIMA Models
    AsSadhan, Basil
    Zeb, Khan
    Al-Muhtadi, Jalal
    Alshebeili, Saleh
    IEEE ACCESS, 2017, 5 : 13501 - 13519
  • [8] Traffic characterization using wavelet-based techniques
    Boulliant, D
    Pruthi, P
    Popescu, A
    PERFORMANCE AND CONTROL OF NETWORK SYSTEMS II, 1998, 3530 : 382 - 391
  • [9] On-line chatter detection using wavelet-based parameter estimation
    Choi, Taejun
    Shin, Yung C.
    American Society of Mechanical Engineers, Manufacturing Engineering Division, MED, 2000, 11 : 141 - 147
  • [10] On-line chatter detection using wavelet-based parameter estimation
    Choi, T
    Shin, YC
    JOURNAL OF MANUFACTURING SCIENCE AND ENGINEERING-TRANSACTIONS OF THE ASME, 2003, 125 (01): : 21 - 28