Online Adaptive Anomaly Detection for Augmented Network Flows

被引:13
|
作者
Ippoliti, Dennis [2 ]
Jiang, Changjun [3 ]
Ding, Zhijun [3 ]
Zhou, Xiaobo [1 ]
机构
[1] Univ Colorado, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[2] Dept Comp Sci, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[3] Tongji Univ, 4800 Caoan Rd, Shanghai 201804, Peoples R China
关键词
Flow-based anomaly detection; online adaptation; support vector machine; dynamic input normalization; Design; Experimentation; Performance; Security;
D O I
10.1145/2934686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Traditional network anomaly detection involves developing models that rely on packet inspection. However, increasing network speeds and use of encrypted protocols make per-packet inspection unsuited for today's networks. One method of overcoming this obstacle is aggregating packet header information and performing flow-based analysis where data flow patterns are examined rather than deep packet inspection. Many existing approaches are special purpose limited to detecting specific behavior. Also, the data reduction inherent in identifying anomalous flows hinders alert correlation. In this article, we propose and develop a dynamic anomaly detection approach for augmented network flows. We sketch network state during flow creation, enabling general-purpose threat detection. We describe an efficient flow augmentation approach based on the count-min sketch that provides per-flow-, per-node-, and per-network-level statistics parallel to flow record generation. We design and develop a support vector machine-based adaptive anomaly detection and correlation mechanism, which is capable of aggregating alerts without a priori alert classification and evolving models online. We further develop a lightweight evolving alert aggregation method and combine it with a confidence forwarding mechanism identifying a small percentage predictions for additional processing. We show effectiveness of our methods on both enterprise and backbone traces. Experimental results demonstrate its ability to maintain high accuracy without the need for offline training.
引用
收藏
页数:28
相关论文
共 50 条
  • [31] Connectionist model for distributed adaptive network anomaly detection system
    Pasha, MF
    Budiarto, R
    Syukur, M
    PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 3915 - 3920
  • [32] Dynamic Local Aggregation Network with Adaptive Clusterer for Anomaly Detection
    Yang, Zhiwei
    Wu, Peng
    Liu, Jing
    Liu, Xiaotao
    COMPUTER VISION - ECCV 2022, PT IV, 2022, 13664 : 404 - 421
  • [33] Memory-augmented appearance-motion network for video anomaly detection
    Wang, Le
    Tian, Junwen
    Zhou, Sanping
    Shi, Haoyue
    Hua, Gang
    PATTERN RECOGNITION, 2023, 138
  • [34] Online Anomaly Detection of Distillation Tower System Using Adaptive Resonance Theory
    Hori, Yoshinari
    Yamamoto, Hiroki
    Suzuki, Tomoko
    Okitsu, Jun
    Nakamura, Tomohiro
    Maeda, Tatsuya
    Matsuo, Toshiaki
    Zabiri, Haslinda Bt
    Tufa, Lemma Dendena
    Marappagounder, Ramasamy
    JOURNAL OF CHEMICAL ENGINEERING OF JAPAN, 2017, 50 (06) : 430 - 438
  • [35] Adaptive Performance Anomaly Detection for Online Service Systems via Pattern Sketching
    Chen, Zhuangbin
    Liu, Jinyang
    Su, Yuxin
    Zhang, Hongyu
    Ling, Xiao
    Yang, Yongqiang
    Lyu, Michael R.
    2022 ACM/IEEE 44TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2022), 2022, : 61 - 72
  • [36] Online Video Anomaly Detection
    Zhang, Yuxing
    Song, Jinchen
    Jiang, Yuehan
    Li, Hongjun
    SENSORS, 2023, 23 (17)
  • [37] Memory-Augmented Spatial-Temporal Consistency Network for Video Anomaly Detection
    Li, Zhangxun
    Zhao, Mengyang
    Zeng, Xinhua
    Wang, Tian
    Pang, Chengxin
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT VI, 2024, 14430 : 95 - 107
  • [38] Investigation of Fuzzy Adaptive Resonance Theory in Network Anomaly Intrusion Detection
    Ngamwitthayanon, Nawa
    Wattanapongsakorn, Naruemon
    Coit, David W.
    ADVANCES IN NEURAL NETWORKS - ISNN 2009, PT 2, PROCEEDINGS, 2009, 5552 : 208 - +
  • [39] A Novel Algorithm for Network Anomaly Detection Using Adaptive Machine Learning
    Kumar, D. Ashok
    Venugopalan, S. R.
    PROGRESS IN ADVANCED COMPUTING AND INTELLIGENT ENGINEERING, VOL 2, 2018, 564 : 59 - 69
  • [40] NEW ADAPTIVE NETWORK ANOMALY DETECTION SYSTEM USING FREQUENT PATTERNS
    Said, Aiman Moyaid
    Dominic, Dhanapal Durai
    Samir, Brahim Belhaouari
    Balfagih, Zain
    4TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGY AND ENGINEERING (ICSTE 2012), 2012, : 369 - 374