Detecting anomalies in backbone network traffic: a performance comparison among several change detection methods

被引:0
|
作者
Callegari, Christian [1 ]
Giordano, Stefano [1 ]
Pagano, Michele [1 ]
Pepe, Teresa [1 ]
机构
[1] Univ Pisa, Dept Informat Engn, Pisa, Italy
关键词
anomaly detection; reversible sketch; heavy hitter; heavy change; multi-chart non-parametric CUSUM algorithm; ALGORITHMS; ATTACKS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the last years, the ever increasing number of network attacks has brought the research attention to the design and development of effective anomaly detection systems. To this aim, the main target is to develop efficient algorithms able to detect abrupt changes in the data, with the smallest detection delay. In this paper, we present a novel method for network anomaly detection, based on the idea of discovering heavy change (HC) in the distribution of the Heavy I-litters in the network traffic, by applying several forecasting algorithms. To assess the validity of the proposed method, we have performed an experimental evaluation phase, during which our system performance have been compared to more 'classical' approaches, such as a standard HC method and the promising CUSUM method. The performance analysis, presented in this paper, demonstrates the effectiveness of the proposed method, showing how it is able to outperform the 'classical' approaches.
引用
收藏
页码:205 / 214
页数:10
相关论文
共 50 条
  • [21] Network traffic anomalies automatic detection in DDoS attacks
    Orekhov, Andrey V.
    Orekhov, Aleksey A.
    VESTNIK SANKT-PETERBURGSKOGO UNIVERSITETA SERIYA 10 PRIKLADNAYA MATEMATIKA INFORMATIKA PROTSESSY UPRAVLENIYA, 2023, 19 (02): : 251 - 263
  • [22] NETWORK TRAFFIC ANOMALY DETECTION USING CLUSTERING TECHNIQUES AND PERFORMANCE COMPARISON
    Liu, Duo
    Lung, Chung-Horng
    Lambadaris, Ioannis
    Seddigh, Nabil
    2013 26TH ANNUAL IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2013, : 345 - 348
  • [23] Detection of Network Anomalies with Machine Learning Methods
    Kara, Ihsan Riza
    Varol, Asaf
    2022 10TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2022,
  • [24] Comparison among several vibronic coupling methods
    Amanda D. Torres
    Carlos E. V. de Moura
    Ricardo R. Oliveira
    Alexandre B. Rocha
    Journal of Molecular Modeling, 2022, 28
  • [25] Comparison among several vibronic coupling methods
    Torres, Amanda D.
    de Moura, Carlos E., V
    Oliveira, Ricardo R.
    Rocha, Alexandre B.
    JOURNAL OF MOLECULAR MODELING, 2022, 28 (09)
  • [26] A COMPARISON of FDD and TDD/TDMA ARCHITECTURES for AIRBORNE BACKBONE NETWORK TRAFFIC
    Adams, Stanley
    Cain, Bibb
    Olds, Keith
    Griessler, Pete
    2008 IEEE MILITARY COMMUNICATIONS CONFERENCE: MILCOM 2008, VOLS 1-7, 2008, : 2868 - 2874
  • [27] A Traffic Decomposition and Prediction Method for Detecting and Tracing Network-Wide Anomalies
    Du, Ping
    Abe, Shunji
    Ji, Yusheng
    Sato, Seisho
    Ishiguro, Makio
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2009, E92D (05) : 929 - 936
  • [28] ODC: a method for online detecting & classifying network-wide traffic anomalies
    Qian, Ye-Kui
    Chen, Ming
    Hao, Qiang
    Liu, Feng-Rong
    Shang, Wen-Zhong
    Tongxin Xuebao/Journal on Communications, 2011, 32 (01): : 111 - 120
  • [29] A divergence-measure based classification method for detecting anomalies in network traffic
    Balagani, Kiran S.
    Phoba, Vir V.
    Kuchimanchi, Gopi K.
    2007 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, SENSING, AND CONTROL, VOLS 1 AND 2, 2007, : 374 - 379
  • [30] Detecting Heavy Change in the Heavy Hitter Distribution of Network Traffic
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    Pepe, Teresa
    2011 7TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2011, : 1298 - 1303