Online Adaptive Anomaly Detection for Augmented Network Flows

被引:13
|
作者
Ippoliti, Dennis [2 ]
Jiang, Changjun [3 ]
Ding, Zhijun [3 ]
Zhou, Xiaobo [1 ]
机构
[1] Univ Colorado, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[2] Dept Comp Sci, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[3] Tongji Univ, 4800 Caoan Rd, Shanghai 201804, Peoples R China
关键词
Flow-based anomaly detection; online adaptation; support vector machine; dynamic input normalization; Design; Experimentation; Performance; Security;
D O I
10.1145/2934686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Traditional network anomaly detection involves developing models that rely on packet inspection. However, increasing network speeds and use of encrypted protocols make per-packet inspection unsuited for today's networks. One method of overcoming this obstacle is aggregating packet header information and performing flow-based analysis where data flow patterns are examined rather than deep packet inspection. Many existing approaches are special purpose limited to detecting specific behavior. Also, the data reduction inherent in identifying anomalous flows hinders alert correlation. In this article, we propose and develop a dynamic anomaly detection approach for augmented network flows. We sketch network state during flow creation, enabling general-purpose threat detection. We describe an efficient flow augmentation approach based on the count-min sketch that provides per-flow-, per-node-, and per-network-level statistics parallel to flow record generation. We design and develop a support vector machine-based adaptive anomaly detection and correlation mechanism, which is capable of aggregating alerts without a priori alert classification and evolving models online. We further develop a lightweight evolving alert aggregation method and combine it with a confidence forwarding mechanism identifying a small percentage predictions for additional processing. We show effectiveness of our methods on both enterprise and backbone traces. Experimental results demonstrate its ability to maintain high accuracy without the need for offline training.
引用
收藏
页数:28
相关论文
共 50 条
  • [41] Fairness based on anomaly score and adaptive weight in network attack detection
    Wen, Xuezhi
    Gao, Meiqi
    Wang, Nan
    Ma, Jiahui
    Zhang, Dalin
    Zhao, Xibin
    Liu, Jiqiang
    INFORMATION SCIENCES, 2024, 678
  • [42] Adaptive Monte Carlo augmented with normalizing flows
    Gabrie, Marylou
    Rotskoff, Grant M.
    Vanden-Eijnden, Eric
    PROCEEDINGS OF THE NATIONAL ACADEMY OF SCIENCES OF THE UNITED STATES OF AMERICA, 2022, 119 (10)
  • [43] Memory-Augmented Autoencoder With Adaptive Reconstruction and Sample Attribution Mining for Hyperspectral Anomaly Detection
    Huo, Yu
    Cheng, Xi
    Lin, Sheng
    Zhang, Min
    Wang, Hai
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 18
  • [44] Quantum normalizing flows for anomaly detection
    Rosenhahn, Bodo
    Hirche, Christoph
    Physical Review A, 2024, 110 (02)
  • [45] Unsupervised Anomaly Detection with a GAN Augmented Autoencoder
    Rafiee, Laya
    Fevens, Thomas
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2020, PT I, 2020, 12396 : 479 - 490
  • [46] Online Privacy-Preserving Data-Driven Network Anomaly Detection
    Kurt, Mehmet Necip
    Yilmaz, Yasin
    Wang, Xiaodong
    Mosterman, Pieter J.
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2022, 40 (03) : 982 - 998
  • [47] Online Data-Centric Anomaly Detection Framework For Sensor Network Deployments
    Abuaitah, Giovani Rimon
    Wang, Bin
    2014 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2014, : 599 - 604
  • [48] A lightweight online network anomaly detection scheme based on date mining methods
    Li, Yang
    Fang, Bin-Xing
    2007 IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS, 2007, : 340 - 341
  • [49] Online Classification of Network Flows
    Tavallaee, Mahbod
    Lu, Wei
    Ghorbani, Ali A.
    2009 7TH ANNUAL COMMUNICATION NETWORKS AND SERVICES RESEARCH CONFERENCE, 2009, : 78 - 85
  • [50] GAD: A Real-Time Gait Anomaly Detection System with Online Adaptive Learning
    Lee, Ming-Chang
    Lin, Jia-Chun
    Katsikas, Sokratis
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2024, 2024, 710 : 308 - 322