Traffic Monitoring and Diagnosis with Multivariate Statistical Network Monitoring: A Case Study

被引:8
|
作者
Camacho, Jose [1 ]
Garcia-Teodoro, Pedro [1 ]
Macia-Fernandez, Gabriel [1 ]
机构
[1] Univ Granada, Dept Signal Theory Telemat & Commun CITIC, Granada, Spain
关键词
ANOMALY DETECTION; SUPPORT; PCA;
D O I
10.1109/SPW.2017.11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The research literature on cybersecurity incident response is very rich in automatic intrusion detection methodologies. The most accepted approach to compare the detection performance of the methods is by using a real traffic data set where normal traffic and anomalies are conveniently combined and labeled. In this paper, we follow this approach in a real network where a number of controlled attacks are launched. Using the captured traffic and the feedback of the IT team of the network, we assess the performance of the Multivariate Statistical Network Monitoring (MSNM) technique proposed in a recent paper, and compare it with the one-class Support Vector Machine (OCSVM). We derive two main conclusions from this real experiment: i) while both approaches showed a similar detection performance, MSNM was superior in diagnosis, a step which is seldom considered in comparisons; and ii) the traffic also presented several non-induced anomalies, initially labeled as normal traffic and clearly detected by both MSNM and OCSVM. This suggests caution in the use of typical performance measures in this type of experiments, since they heavily rely on the correctness of the labeling. With this experiment, we illustrate that the MSNM approach is coherent with the needs of an incident response team: it provides an adequate priorization of the security events and gives support to diagnosis, so that in less time and with less resources the team can be more effective.
引用
收藏
页码:241 / 246
页数:6
相关论文
共 50 条
  • [1] Multivariate statistical monitoring of buildings. Case study: Energy monitoring of a social housing building
    Burgas, Llorenc
    Melendez, Joaquim
    Colomer, Joan
    Massana, Joaquim
    Pous, Carles
    [J]. ENERGY AND BUILDINGS, 2015, 103 : 338 - 351
  • [2] An intelligent system for multivariate statistical process monitoring and diagnosis
    Tatara, E
    Çinar, A
    [J]. ISA TRANSACTIONS, 2002, 41 (02) : 255 - 270
  • [3] Multivariate statistical monitoring procedures for fermentation supervision: An industrial case study
    Montague, GA
    Hiden, HG
    Kornfeld, G
    [J]. COMPUTER APPLICATIONS IN BIOTECHNOLOGY 1998: HORIZON OF BIOPROCESS SYSTEMS ENGINEERING IN 21ST CENTURY, 1998, : 399 - 404
  • [4] A Study on The WAN Network Traffic Monitoring
    Ren, Hao Li
    Liang, Xiao Peng
    Peng, Kong Yang
    [J]. MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 6419 - 6422
  • [5] Multivariate statistical monitoring of batch processes: an industrial case study of fermentation supervision
    Albert, S
    Kinley, RD
    [J]. TRENDS IN BIOTECHNOLOGY, 2001, 19 (02) : 53 - 62
  • [6] MULTIVARIATE STATISTICAL PROCESS MONITORING
    Sliskovic, Drazen
    Grbic, Ratko
    Hocenski, Zeljko
    [J]. TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2012, 19 (01): : 33 - 41
  • [7] Detectability study for statistical monitoring of multivariate dynamic processes
    Chen, Nan
    Zhou, Shiyu
    [J]. IIE TRANSACTIONS, 2009, 41 (07) : 593 - 604
  • [8] PCA-based multivariate statistical network monitoring for anomaly detection
    Camacho, Jose
    Perez-Villegas, Alejandro
    Garcia-Teodoro, Pedro
    Macia-Fernandez, Gabriel
    [J]. COMPUTERS & SECURITY, 2016, 59 : 118 - 137
  • [9] Study on prioritization of network traffic for wireless traffic monitoring systems
    Xu, HJ
    He, XJ
    [J]. CISST '04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON IMAGING SCIENCE, SYSTEMS, AND TECHNOLOGY, 2004, : 35 - 38
  • [10] MULTIVARIATE STATISTICAL MONITORING OF POLYPROPYLENE PRODUCTION
    SKAGERBERG, B
    LEHTINEN, J
    WIKLUND, J
    [J]. PLASTICS RUBBER AND COMPOSITES PROCESSING AND APPLICATIONS, 1992, 18 (05): : 299 - 305