Detecting anomalies in backbone network traffic: a performance comparison among several change detection methods

被引:0
|
作者
Callegari, Christian [1 ]
Giordano, Stefano [1 ]
Pagano, Michele [1 ]
Pepe, Teresa [1 ]
机构
[1] Univ Pisa, Dept Informat Engn, Pisa, Italy
关键词
anomaly detection; reversible sketch; heavy hitter; heavy change; multi-chart non-parametric CUSUM algorithm; ALGORITHMS; ATTACKS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the last years, the ever increasing number of network attacks has brought the research attention to the design and development of effective anomaly detection systems. To this aim, the main target is to develop efficient algorithms able to detect abrupt changes in the data, with the smallest detection delay. In this paper, we present a novel method for network anomaly detection, based on the idea of discovering heavy change (HC) in the distribution of the Heavy I-litters in the network traffic, by applying several forecasting algorithms. To assess the validity of the proposed method, we have performed an experimental evaluation phase, during which our system performance have been compared to more 'classical' approaches, such as a standard HC method and the promising CUSUM method. The performance analysis, presented in this paper, demonstrates the effectiveness of the proposed method, showing how it is able to outperform the 'classical' approaches.
引用
收藏
页码:205 / 214
页数:10
相关论文
共 50 条
  • [41] A comparison of landscape change detection methods
    Edmonds, CM
    Neale, AC
    Heggem, DT
    Wickham, JD
    Jones, KB
    MANAGING FOR HEALTHY ECOSYSTEMS, 2003, : 403 - 411
  • [42] Automatic Detection of Computer Network Traffic Anomalies based on Eccentricity Analysis
    Martins, Rodrigo Siqueira
    Angelov, Plamen
    Jales Costa, Bruno Sielly
    2018 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS (FUZZ-IEEE), 2018,
  • [43] Identifying Anomalies in Network Traffic using Hybrid Intrusion Detection System
    Garg, Akash
    Maheshwari, Prachi
    2016 3RD INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2016,
  • [44] Wavelet-based real time detection of network traffic anomalies
    Department of Computer Science and Engineering, University of South Carolina, 301 Main St, Columbia, SC29208, United States
    不详
    Int. J. Netw. Secur., 2008, 3 (309-320):
  • [45] WK-FNN DESIGN FOR DETECTION OF ANOMALIES IN THE COMPUTER NETWORK TRAFFIC
    Protic, Danijela
    Stankovic, Miomir
    Antic, Vladimir
    FACTA UNIVERSITATIS-SERIES ELECTRONICS AND ENERGETICS, 2022, 35 (02) : 269 - 282
  • [46] Wavelet-based real time detection of network traffic anomalies
    Huang, Chin-Tser
    Thareja, Sachin
    Shin, Yong-June
    2006 SECURECOMM AND WORKSHOPS, 2006, : 473 - +
  • [47] Using Internet traffic self-similarity for detection of network anomalies
    Dobrescu, R.
    Dobrescu, M.
    Hossu, D.
    Taralunga, S.
    OPTIM 2008: PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON OPTIMIZATION OF ELECTRICAL AND ELECTRONIC EQUIPMENT, VOL III, 2008, : 81 - 86
  • [48] Bringing Data Analytics to the Network Nodes for Efficient Traffic Anomalies Detection
    Vela, Alba P.
    Ruiz, Marc
    Velasco, Luis
    2017 19TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON), 2017,
  • [49] COMPARISON OF SEVERAL DETECTION METHODS FOR TOXAPHENE RESIDUE ANALYSIS
    LACH, G
    PARLAR, H
    TOXICOLOGICAL AND ENVIRONMENTAL CHEMISTRY, 1991, 31-2 : 209 - 219
  • [50] Comparative analysis of several vehicle detection methods in urban traffic scenes
    Zhao, Minhui
    Zhao, Chihang
    Qi, Xingzhi
    2016 10TH INTERNATIONAL CONFERENCE ON SENSING TECHNOLOGY (ICST), 2016,