Anomaly Detection using Wavelet-Based Estimation of LRD in Packet and Byte Count of Control Traffic

被引:0
|
作者
Zeb, Khan [1 ,2 ]
AsSadhan, Basil [1 ,2 ]
Al-Muhtadi, Jalal [1 ,3 ]
Alshebeili, Saleh [2 ,4 ]
机构
[1] King Saud Univ, Ctr Excellence Informat Assurance CoEIA, Riyadh, Saudi Arabia
[2] King Saud Univ, Coll Engn, Dept Elect Engn, Riyadh, Saudi Arabia
[3] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Sci, Riyadh, Saudi Arabia
[4] King Saud Univ, KACST TIC RF & Photon E Soc RFTONICS, Riyadh, Saudi Arabia
关键词
anomaly detection; LRD; control traffic; network traffic analysis; wavelet;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The detection of anomalous behavior such as low volume attacks and abnormalities in today's large volume of Internet traffic has become a challenging problem in the network community. An efficient and real-time detection of anomaly traffic is crucial in order to rapidly diagnose and mitigate the anomaly, and to recover the resulting malfunction. In this paper, we present an efficient anomaly detection method based on the estimation of long-range dependence (LRD) behavior in packet and byte count of the aggregated control traffic. This method surrogates Internet aggregated whole traffic (i.e., control plus data) by the aggregated control traffic and detects anomaly traffic through the wavelet-based estimation of LRD behavior in the corresponding control traffic. Since Internet traffic exhibits LRD behavior during benign normal condition, deviation from this behavior can indicate an anomalous behavior. Experiments on the KSU dataset demonstrate that this method not only significantly improves the process of anomaly detection by considerably reducing the large-volume of traffic to be processed but also achieves a high detection effect. Because the control traffic constitute a small fraction of the whole traffic, and usually most of the attacks are manifested and carried out in the control traffic; therefore, surrogating the whole traffic by the control traffic increases the detection efficacy.
引用
收藏
页码:316 / 321
页数:6
相关论文
共 50 条
  • [21] The wavelet-based multi-resolution motion estimation using temporal aliasing detection
    Lee, Teahyung
    Anderson, David V.
    VISUAL COMMUNICATIONS AND IMAGE PROCESSING 2007, PTS 1 AND 2, 2007, 6508
  • [22] Wavelet-Based Normalized Flow for Anomaly Detection in Photovoltaic Electroluminescent With Nonstationary Textures
    Yang, Bokang
    Zhang, Zhe
    Ma, Jie
    IEEE SENSORS JOURNAL, 2025, 25 (01) : 891 - 903
  • [23] Wavelet-based analysis of Hurst parameter estimation for self-similar traffic
    Li, YL
    Liu, GZ
    Li, HL
    Hou, XS
    2002 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, VOLS I-IV, PROCEEDINGS, 2002, : 2061 - 2064
  • [24] Correspondence detection using wavelet-based attribute vectors
    Xue, Z
    Shen, DG
    Davatzikos, C
    MEDICAL IMAGE COMPUTING AND COMPUTER-ASSISTED INTERVENTION - MICCAI 2003, PT 2, 2003, 2879 : 762 - 770
  • [25] Anomaly Detection of Network Traffic Based on Analytical Discrete Wavelet Transform
    Salagean, Marius
    Firoiu, Ioana
    PROCEEDINGS OF THE 2010 8TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS (COMM), 2010, : 49 - 52
  • [26] Network Traffic Anomaly Detection Based on Self-Similarity Using HHT and Wavelet Transform
    Cheng, Xiaorong
    Xie, Kun
    Wang, Dong
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 1, PROCEEDINGS, 2009, : 710 - 713
  • [27] Web traffic demand forecasting using wavelet-based multiscale decomposition
    Aussem, A
    Murtagh, F
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2001, 16 (02) : 215 - 236
  • [28] Spatiotemporal Forecasting of Traffic Flow Using Wavelet-Based Temporal Attention
    Jakhmola, Yash
    Panja, Madhurima
    Mishra, Nitish Kumar
    Ghosh, Kripabandhu
    Kumar, Uttam
    Chakraborty, Tanujit
    IEEE ACCESS, 2024, 12 : 188797 - 188812
  • [29] Wavelet-Based Poisson Rate Estimation Using the Skellam Distribution
    Hirakawa, Keigo
    Baqai, Farhan
    Wolfe, Patrick J.
    COMPUTATIONAL IMAGING VII, 2009, 7246
  • [30] Wavelet-Based Estimation of Hurst Exponent Using Neural Network
    Kirichenko, Lyudmyla
    Pavlenko, Kyrylo
    Khatsko, Daryna
    2022 IEEE 17TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND INFORMATION TECHNOLOGIES (CSIT), 2022, : 40 - 43