Network Anomaly Detection Based on Wavelet Analysis

被引:125
|
作者
Lu, Wei [1 ]
Ghorbani, Ali A. [1 ]
机构
[1] Univ New Brunswick, Informat Secur Ctr Excellence, Fredericton, NB E3B 5A3, Canada
关键词
50;
D O I
10.1155/2009/837601
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Signal processing techniques have been applied recently for analyzing and detecting network anomalies due to their potential to find novel or unknown intrusions. In this paper, we propose a new network signal modelling technique for detecting network anomalies, combining the wavelet approximation and system identification theory. In order to characterize network traffic behaviors, we present fifteen features and use them as the input signals in our system. We then evaluate our approach with the 1999 DARPA intrusion detection dataset and conduct a comprehensive analysis of the intrusions in the dataset. Evaluation results show that the approach achieves high-detection rates in terms of both attack instances and attack types. Furthermore, we conduct a full day's evaluation in a real large-scale WiFi ISP network where five attack types are successfully detected from over 30 millions flows. Copyright (C) 2009 W. Lu and A. A. Ghorbani.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Network Anomaly Detection Based on Wavelet Analysis
    Wei Lu
    Ali A. Ghorbani
    EURASIP Journal on Advances in Signal Processing, 2009
  • [2] Network Traffic Anomaly Detection Based on Wavelet Analysis
    Du, Zhen
    Ma, Lipeng
    Li, Huakang
    Li, Qun
    Sun, Guozi
    Liu, Zichang
    2018 IEEE/ACIS 16TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT AND APPLICATION (SERA), 2018, : 94 - 101
  • [3] MQPSO Based on Wavelet Neural Network for Network Anomaly Detection
    Liu, Li-li
    Liu, Yuan
    2009 5TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-8, 2009, : 4643 - +
  • [4] Anomaly detection of network traffic based on wavelet packet
    Gao, Jun
    Hu, Guangmin
    Yao, Xingmiao
    Chang, Rocky K. C.
    2006 ASIA-PACIFIC CONFERENCE ON COMMUNICATION, VOLS 1 AND 2, 2006, : 660 - 664
  • [5] Combining Wavelet Analysis and CUSUM Algorithm for Network Anomaly Detection
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    Pepe, Teresa
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [6] Wavelet Fuzzy Neural Network based on modified QPSO for Network Anomaly Detection
    Ma, Ruhui
    Liu, Yuan
    INFORMATION TECHNOLOGY FOR MANUFACTURING SYSTEMS, PTS 1 AND 2, 2010, : 1378 - +
  • [7] Network anomaly detection based on wavelet fuzzy neural network with modified QPSO
    Ma, Ruhui
    Liu, Yuan
    Lin, Xing
    INTERNATIONAL SYMPOSIUM ON ADVANCES IN COMPUTER AND SENSOR NETWORKS AND SYSTEMS, PROCEEDINGS: IN CELEBRATION OF 60TH BIRTHDAY OF PROF. S. SITHARAMA IYENGAR FOR HIS CONTRIBUTIONS TO THE SCIENCE OF COMPUTING, 2008, : 228 - 235
  • [8] Network Anomaly Detection Based on Wavelet Fuzzy Neural Network with Modified QPSO
    Ma, Ruhui
    Liu, Yuan
    Lin, Xing
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2009, 5 (01) : 49 - 49
  • [9] Anomaly Detection of Network Traffic Based on Analytical Discrete Wavelet Transform
    Salagean, Marius
    Firoiu, Ioana
    PROCEEDINGS OF THE 2010 8TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS (COMM), 2010, : 49 - 52
  • [10] Hybrid QPSO based wavelet neural networks for network anomaly detection
    Ma, Ruhui
    Liu, Yuan
    Lin, Xing
    SECOND WORKSHOP ON DIGITAL MEDIA AND ITS APPLICATION IN MUSEUM & HERITAGE, PROCEEDINGS, 2007, : 442 - +