Network anomaly detection based on clustering of sequence patterns

被引:0
|
作者
Noh, Sang-Kyun
Kim, Yong-Min
Kim, DongKook
Noh, Bong-Nam [1 ]
机构
[1] Chonnam Natl Univ, Interdisciplinary Program Informat Secur, Kwangju 500757, South Korea
[2] Chonnam Natl Univ, Dept Elect Commerce, Yeosu 550749, South Korea
[3] Chonnam Natl Univ, Div Elect Comp & Informat Engn, Kwangju 500757, South Korea
来源
COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 2 | 2006年 / 3981卷
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Anomaly detection is a method for determining behaviors which do not accord with normal ones. It is mostly used for detecting abnormal behaviors, mutational and unknown attacks. In this paper, we propose a technique that generates patterns about network-based normal behaviors in blocks of a TCP network session for the anomaly detection. One session is expressed as one pattern based on a stream of the packets in the session, and thus the pattern we generate has a sequential feature. We use the ROCK algorithm to cluster the sequence patterns which have categorical attributes. This algorithm performs clustering based on our similarity function which uses Dynamic Programming. The many sequence patterns of the normal behaviors can be reduced to several representative sequence patterns using the clustering. Our detecting sensor uses profiling dataset that are constructed by the representative sequence patterns of normal behaviors. We show the effectiveness of proposed model by using results from the 1999 DARPA Intrusion Detection Evaluation.
引用
收藏
页码:349 / 358
页数:10
相关论文
共 50 条
  • [21] Network Anomaly Detection using Co-clustering
    Papalexakis, Evangelos E.
    Beutel, Alex
    Steenkiste, Peter
    2012 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM), 2012, : 403 - 410
  • [22] Anomaly Detection of Wind Turbine Driveline Based on Sequence Decomposition Interactive Network
    Lyu, Qiucheng
    He, Yuwei
    Wu, Shijing
    Li, Deng
    Wang, Xiaosun
    SENSORS, 2023, 23 (21)
  • [23] Anomaly Detection of Target Dynamics Based on Clustering
    Jian, Zhang
    Qing, Ye
    Ti, Zhou
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 287 - 291
  • [24] A Novel Model for Anomaly Detection in Network Traffic Based on Support Vector Machine and Clustering
    Ma, Qian
    Sun, Cong
    Cui, Baojiang
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [25] Network Traffic Anomaly Detection Using Adaptive Density-based Fuzzy Clustering
    Liu, Duo
    Lung, Chung-Horng
    Seddigh, Nabil
    Nandy, Biswajit
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 823 - 830
  • [26] Maritime Anomaly Detection using Density-based Clustering and Recurrent Neural Network
    Zhao, Liangbin
    Shi, Guoyou
    JOURNAL OF NAVIGATION, 2019, 72 (04): : 894 - 916
  • [27] Anomaly Detection Method of Distribution Network Line Loss Based on Hybrid Clustering and LSTM
    Liu Keyan
    Jia Dongli
    Kang Zhongjian
    Luo Lin
    Journal of Electrical Engineering & Technology, 2022, 17 : 1131 - 1141
  • [28] UADNet: A Joint Unmixing and Anomaly Detection Network Based on Deep Clustering for Hyperspectral Image
    Liu, Wendi
    Ma, Yong
    Wang, Xiaozhu
    Huang, Jun
    Chen, Qihai
    Li, Hao
    Mei, Xiaoguang
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 (1-19): : 1 - 19
  • [29] Unsupervised Anomaly Detection for Network Flow Using Immune Network Based K-means Clustering
    Shi, Yuanquan
    Peng, Xiaoning
    Li, Renfa
    Zhang, Yu
    DATA SCIENCE, PT 1, 2017, 727 : 386 - 399
  • [30] Anomaly Detection Method of Distribution Network Line Loss Based on Hybrid Clustering and LSTM
    Liu Keyan
    Jia Dongli
    Kang Zhongjian
    Luo Lin
    JOURNAL OF ELECTRICAL ENGINEERING & TECHNOLOGY, 2022, 17 (02) : 1131 - 1141