Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling

被引:3
|
作者
Uchida, Masato [1 ]
Nawata, Shuichi [2 ]
Gu, Yu [3 ]
Tsuru, Masato [4 ]
Oie, Yuji [4 ]
机构
[1] Chiba Inst Technol, Fac Engn, Dept Elect Elect & Comp Engn, Narashino, Chiba 2750016, Japan
[2] KDDI R&D Labs Inc, Fujimino 3568502, Japan
[3] Amazon Web Serv, Seattle, WA 98109 USA
[4] Kyushu Inst Technol, Network Design Res Ctr, Iizuka, Fukuoka 8208502, Japan
基金
日本学术振兴会;
关键词
anomaly detection; packet sampling;
D O I
10.1587/transcom.E95.B.2358
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
We propose an anomaly detection method for finding patterns in network traffic that do not conform to legitimate (i.e., normal) behavior. The proposed method trains a baseline model describing the normal behavior of network traffic without using manually labeled traffic data. The trained baseline model is used as the basis for comparison with the audit network traffic. This anomaly detection works in an unsupervised manner through the use of time-periodic packet sampling, which is used in a manner that differs from its intended purpose the lossy nature of packet sampling is used to extract normal packets from the unlabeled original traffic data. Evaluation using actual traffic traces showed that the proposed method has false positive and false negative rates in the detection of anomalies regarding TCP SYN packets comparable to those of a conventional method that uses manually labeled traffic data to train the baseline model. Performance variation due to the probabilistic nature of sampled traffic data is mitigated by using ensemble anomaly detection that collectively exploits multiple baseline models in parallel. Alarm sensitivity is adjusted for the intended use by using maximum- and minimum-based anomaly detection that effectively take advantage of the performance variations among the multiple baseline models. Testing using actual traffic traces showed that the proposed anomaly detection method performs as well as one using manually labeled traffic data and better than one using randomly sampled (unlabeled) traffic data.
引用
收藏
页码:2358 / 2367
页数:10
相关论文
共 50 条
  • [41] RESIST: Robust Transformer for Unsupervised Time Series Anomaly Detection
    Najari, Naji
    Berlemont, Samuel
    Lefebvre, Gregoire
    Duffner, Stefan
    Garcia, Christophe
    ADVANCED ANALYTICS AND LEARNING ON TEMPORAL DATA, AALTD 2022, 2023, 13812 : 66 - 82
  • [42] Denoising Architecture for Unsupervised Anomaly Detection in Time-Series
    Skaf, Wadie
    Horvath, Tomas
    NEW TRENDS IN DATABASE AND INFORMATION SYSTEMS, ADBIS 2022, 2022, 1652 : 178 - 187
  • [43] Advancing unsupervised anomaly detection with normalizing flow and multi-scale ensemble learning
    Campos-Romero, Miguel
    Carranza-Garcia, Manuel
    Riquelme, Jose C.
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 137
  • [44] An unsupervised deep learning ensemble model for anomaly detection in static attributed social networks
    Khan W.
    Haroon M.
    International Journal of Cognitive Computing in Engineering, 2022, 3 : 153 - 160
  • [45] Targeted model energy transfer using a time-periodic support
    Dohnal, Fadi
    SCHWINGUNGEN 2017: BERECHNUNG, UBERWACHUNG, ANWENDUNG, 2017, 2295 : 363 - 374
  • [46] Time-periodic solutions of Hamiltonian PDEs using pseudoholomorphic curves
    Fabert, Oliver
    Lamoree, Niek
    ALGEBRAIC AND GEOMETRIC TOPOLOGY, 2023, 23 (01): : 461 - 508
  • [47] Collision Detection for Robot Manipulators Using Unsupervised Anomaly Detection Algorithms
    Park, Kyu Min
    Park, Younghyo
    Yoon, Sangwoong
    Park, Frank C.
    IEEE-ASME TRANSACTIONS ON MECHATRONICS, 2022, 27 (05) : 2841 - 2851
  • [48] Single-Step Sampling Approach for Unsupervised Anomaly Detection of Brain MRI Using Denoising Diffusion Models
    Damudi, Mohammed Z.
    Kini, Anita S.
    INTERNATIONAL JOURNAL OF BIOMEDICAL IMAGING, 2024, 2024 (01)
  • [49] Unsupervised Anomaly Detection for Time Series Data of Spacecraft Using Multi-Task Learning
    Yang, Kaifei
    Wang, Yakun
    Han, Xiaodong
    Cheng, Yuehua
    Guo, Lifang
    Gong, Jianglei
    APPLIED SCIENCES-BASEL, 2022, 12 (13):
  • [50] Unsupervised Anomaly Detection in Energy Time Series Data using Variational Recurrent Autoencoders with Attention
    Pereira, Joao
    Silveira, Margarida
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2018, : 1275 - 1282