Online Adaptive Anomaly Detection for Augmented Network Flows

被引:13
|
作者
Ippoliti, Dennis [2 ]
Jiang, Changjun [3 ]
Ding, Zhijun [3 ]
Zhou, Xiaobo [1 ]
机构
[1] Univ Colorado, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[2] Dept Comp Sci, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[3] Tongji Univ, 4800 Caoan Rd, Shanghai 201804, Peoples R China
关键词
Flow-based anomaly detection; online adaptation; support vector machine; dynamic input normalization; Design; Experimentation; Performance; Security;
D O I
10.1145/2934686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Traditional network anomaly detection involves developing models that rely on packet inspection. However, increasing network speeds and use of encrypted protocols make per-packet inspection unsuited for today's networks. One method of overcoming this obstacle is aggregating packet header information and performing flow-based analysis where data flow patterns are examined rather than deep packet inspection. Many existing approaches are special purpose limited to detecting specific behavior. Also, the data reduction inherent in identifying anomalous flows hinders alert correlation. In this article, we propose and develop a dynamic anomaly detection approach for augmented network flows. We sketch network state during flow creation, enabling general-purpose threat detection. We describe an efficient flow augmentation approach based on the count-min sketch that provides per-flow-, per-node-, and per-network-level statistics parallel to flow record generation. We design and develop a support vector machine-based adaptive anomaly detection and correlation mechanism, which is capable of aggregating alerts without a priori alert classification and evolving models online. We further develop a lightweight evolving alert aggregation method and combine it with a confidence forwarding mechanism identifying a small percentage predictions for additional processing. We show effectiveness of our methods on both enterprise and backbone traces. Experimental results demonstrate its ability to maintain high accuracy without the need for offline training.
引用
收藏
页数:28
相关论文
共 50 条
  • [11] GTF: An Adaptive Network Anomaly Detection Method at the Network Edge
    Li, Renjie
    Zhou, Zhou
    Liu, Xuan
    Li, Da
    Yang, Wei
    Li, Shu
    Liu, Qingyun
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [12] Online and Scalable Unsupervised Network Anomaly Detection Method
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (01): : 34 - 47
  • [13] Massively Parallel Anomaly Detection in Online Network Measurement
    Shanbhag, Shashank
    Wolf, Tilman
    2008 PROCEEDINGS OF 17TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, VOLS 1 AND 2, 2008, : 261 - 266
  • [14] A Hybrid Online Offline System for Network Anomaly Detection
    Odiathevar, Murugaraj
    Seah, Winston K. G.
    Frean, Marcus
    2019 28TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2019,
  • [15] Self-adaptive cloud monitoring with online anomaly detection
    Wang, Tao
    Xu, Jiwei
    Zhang, Wenbo
    Gu, Zeyu
    Zhong, Hua
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 80 : 89 - 101
  • [16] Adaptive and online data anomaly detection for wireless sensor systems
    Rassam, Murad A.
    Maarof, Mohd Aizaini
    Zainal, Anazida
    KNOWLEDGE-BASED SYSTEMS, 2014, 60 : 44 - 57
  • [17] Self-adaptive and dynamic clustering for online anomaly detection
    Lee, Seungmin
    Kim, Gisung
    Kim, Sehun
    EXPERT SYSTEMS WITH APPLICATIONS, 2011, 38 (12) : 14891 - 14898
  • [18] Improved Adaptive Model Pools for Online Anomaly Detection Algorithms
    Xiang, Qiu-Yan
    Zi, Ling-Ling
    Cong, Xin
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2024, 52 (07): : 2503 - 2514
  • [19] An adaptive method for anomaly detection in symmetric network traffic
    Yu, Ming
    Zhou, Xi-Yuan
    COMPUTERS & SECURITY, 2007, 26 (06) : 427 - 433
  • [20] Augmented Time Regularized Generative Adversarial Network (ATR-GAN) for Data Augmentation in Online Process Anomaly Detection
    Li, Yuxuan
    Shi, Zhangyue
    Liu, Chenang
    Tian, Wenmeng
    Kong, Zhenyu
    Williams, Christopher B.
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2022, 19 (04) : 3338 - 3355