Detecting Network-wide Traffic Anomalies based on Spatial HMM

被引:2
|
作者
Li, Min [1 ]
Yu, Shunzheng [1 ]
He, Li [1 ]
机构
[1] Sun Yat Sen Univ, Dept Elect & Commun Engn, Guangzhou 510275, Guangdong, Peoples R China
关键词
D O I
10.1109/NPC.2008.89
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In contrast to many techniques exploiting temporal patterns of traffic from a single network element, network-wide traffic analysis mainly focuses on the spatial behavior across the whole network. This paper proposes a spatial hidden Markov model (SHMM) to learn the normal patterns of network-wide traffic. Combined with topology information, SHMM models traffic volumes on links as probabilistic outputs of underlying interactions between routers. Based on a trained SHMM, a nonparametric CUSUM algorithm is used to track the change of entropy of observation sequences in different sliding windows for anomaly detection. Background traffic collected from real network and synthetic anomalies are used for validation of the detection method. The results prove our method effective for network-wide traffic anomaly detection.
引用
收藏
页码:198 / 203
页数:6
相关论文
共 50 条
  • [1] Detecting Network-wide Traffic Anomalies Based on Robust Multivariate Probabilistic Calibration Model
    Li, Yuchong
    Luo, Xingguo
    Li, Bainan
    [J]. 2015 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2015), 2015, : 1323 - 1328
  • [2] A Traffic Decomposition and Prediction Method for Detecting and Tracing Network-Wide Anomalies
    Du, Ping
    Abe, Shunji
    Ji, Yusheng
    Sato, Seisho
    Ishiguro, Makio
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2009, E92D (05) : 929 - 936
  • [3] Diagnosing network-wide traffic anomalies
    Lakhina, A
    Crovella, M
    Diot, C
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2004, 34 (04) : 219 - 230
  • [4] NMF-NAD: Detecting network-wide traffic anomaly based on NMF
    Wei, Xiang-Lin
    Chen, Ming
    Zhang, Guo-Min
    Huang, Jian-Jun
    [J]. Tongxin Xuebao/Journal on Communications, 2012, 33 (04): : 54 - 61
  • [5] Detecting Distributed Network Traffic Anomaly with Network-Wide Correlation Analysis
    Li Zonglin
    Hu Guangmin
    Yao Xingmiao
    Yang Dan
    [J]. EURASIP Journal on Advances in Signal Processing, 2009
  • [6] Detecting Distributed Network Traffic Anomaly with Network-Wide Correlation Analysis
    Li Zonglin
    Hu Guangmin
    Yao Xingmiao
    Yang Dan
    [J]. EURASIP JOURNAL ON ADVANCES IN SIGNAL PROCESSING, 2009,
  • [7] A Method for Detecting Wide-scale Network Traffic Anomalies
    Wang Minghua(National Computer Network Emergency Response Technical Team/Coordination Center(CNCERT/CC)
    [J]. ZTE Communications, 2007, (04) : 19 - 23
  • [8] A network-wide traffic anomaly detection method based on HSMM
    Min, Li
    Shun-Zheng, Yu
    [J]. 2006 INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS PROCEEDINGS, VOLS 1-4: VOL 1: SIGNAL PROCESSING, 2006, : 1636 - +
  • [9] Detecting network-wide abnormal behavior for network data streams based on sketch
    Zhou, Aiping
    Shi, Yiwei
    Zhu, Huisheng
    Li, Jinhai
    Zhu, Chengang
    [J]. 2018 SIXTH INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA (CBD), 2018, : 118 - 123
  • [10] URBAN NETWORK-WIDE TRAFFIC VARIABLES AND THEIR RELATIONS
    ARDEKANI, S
    HERMAN, R
    [J]. TRANSPORTATION SCIENCE, 1987, 21 (01) : 1 - 16