Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling

被引:3
|
作者
Uchida, Masato [1 ]
Nawata, Shuichi [2 ]
Gu, Yu [3 ]
Tsuru, Masato [4 ]
Oie, Yuji [4 ]
机构
[1] Chiba Inst Technol, Fac Engn, Dept Elect Elect & Comp Engn, Narashino, Chiba 2750016, Japan
[2] KDDI R&D Labs Inc, Fujimino 3568502, Japan
[3] Amazon Web Serv, Seattle, WA 98109 USA
[4] Kyushu Inst Technol, Network Design Res Ctr, Iizuka, Fukuoka 8208502, Japan
基金
日本学术振兴会;
关键词
anomaly detection; packet sampling;
D O I
10.1587/transcom.E95.B.2358
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
We propose an anomaly detection method for finding patterns in network traffic that do not conform to legitimate (i.e., normal) behavior. The proposed method trains a baseline model describing the normal behavior of network traffic without using manually labeled traffic data. The trained baseline model is used as the basis for comparison with the audit network traffic. This anomaly detection works in an unsupervised manner through the use of time-periodic packet sampling, which is used in a manner that differs from its intended purpose the lossy nature of packet sampling is used to extract normal packets from the unlabeled original traffic data. Evaluation using actual traffic traces showed that the proposed method has false positive and false negative rates in the detection of anomalies regarding TCP SYN packets comparable to those of a conventional method that uses manually labeled traffic data to train the baseline model. Performance variation due to the probabilistic nature of sampled traffic data is mitigated by using ensemble anomaly detection that collectively exploits multiple baseline models in parallel. Alarm sensitivity is adjusted for the intended use by using maximum- and minimum-based anomaly detection that effectively take advantage of the performance variations among the multiple baseline models. Testing using actual traffic traces showed that the proposed anomaly detection method performs as well as one using manually labeled traffic data and better than one using randomly sampled (unlabeled) traffic data.
引用
收藏
页码:2358 / 2367
页数:10
相关论文
共 50 条
  • [22] UNSUPERVISED ANOMALY DETECTION FOR TIME SERIES WITH OUTLIER EXPOSURE
    Feng, Jiaming
    Huang, Zheng
    Guo, Jie
    Qiu, Weidong
    33RD INTERNATIONAL CONFERENCE ON SCIENTIFIC AND STATISTICAL DATABASE MANAGEMENT (SSDBM 2021), 2020, : 1 - 12
  • [23] Unsupervised diffusion based anomaly detection for time series
    Zuo, Haiwei
    Zhu, Aiqun
    Zhu, Yanping
    Liao, Yinping
    Li, Shiman
    Chen, Yun
    APPLIED INTELLIGENCE, 2024, 54 (19) : 8968 - 8981
  • [24] Unsupervised Anomaly Detection Approach for Multivariate Time Series
    Zhou, Yuanlin
    Song, Yingxuan
    Qian, Mideng
    2021 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C 2021), 2021, : 229 - 235
  • [25] USAD : UnSupervised Anomaly Detection on Multivariate Time Series
    Audibert, Julien
    Michiardi, Pietro
    Guyard, Frederic
    Marti, Sebastien
    Zuluaga, Maria A.
    KDD '20: PROCEEDINGS OF THE 26TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2020, : 3395 - 3404
  • [26] Anomaly detection in multivariate time series data using deep ensemble models
    Iqbal, Amjad
    Amin, Rashid
    Alsubaei, Faisal S.
    Alzahrani, Abdulrahman
    PLOS ONE, 2024, 19 (06):
  • [27] DELR: A double-level ensemble learning method for unsupervised anomaly detection
    Zhang, Jia
    Li, Zhiyong
    Nai, Ke
    Gu, Yu
    Sallam, Ahmed
    KNOWLEDGE-BASED SYSTEMS, 2019, 181
  • [28] Unsupervised Ensemble-Kernel Principal Component Analysis for Hyperspectral Anomaly Detection
    Merrill, Nicholas
    Olson, Colin C.
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2020), 2020, : 507 - 515
  • [29] Time Series Analysis: Unsupervised Anomaly Detection Beyond Outlier Detection
    Landauer, Max
    Wurzenberger, Markus
    Skopik, Florian
    Settanni, Giuseppe
    Filzmoser, Peter
    INFORMATION SECURITY PRACTICE AND EXPERIENCE (ISPEC 2018), 2018, 11125 : 19 - 36
  • [30] Time Series Anomaly Detection with Multiresolution Ensemble Decoding
    Shen, Lifeng
    Yu, Zhongzhong
    Ma, Qianli
    Kwok, James T.
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 9567 - 9575