Traffic Monitoring and Diagnosis with Multivariate Statistical Network Monitoring: A Case Study

被引:8
|
作者
Camacho, Jose [1 ]
Garcia-Teodoro, Pedro [1 ]
Macia-Fernandez, Gabriel [1 ]
机构
[1] Univ Granada, Dept Signal Theory Telemat & Commun CITIC, Granada, Spain
关键词
ANOMALY DETECTION; SUPPORT; PCA;
D O I
10.1109/SPW.2017.11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The research literature on cybersecurity incident response is very rich in automatic intrusion detection methodologies. The most accepted approach to compare the detection performance of the methods is by using a real traffic data set where normal traffic and anomalies are conveniently combined and labeled. In this paper, we follow this approach in a real network where a number of controlled attacks are launched. Using the captured traffic and the feedback of the IT team of the network, we assess the performance of the Multivariate Statistical Network Monitoring (MSNM) technique proposed in a recent paper, and compare it with the one-class Support Vector Machine (OCSVM). We derive two main conclusions from this real experiment: i) while both approaches showed a similar detection performance, MSNM was superior in diagnosis, a step which is seldom considered in comparisons; and ii) the traffic also presented several non-induced anomalies, initially labeled as normal traffic and clearly detected by both MSNM and OCSVM. This suggests caution in the use of typical performance measures in this type of experiments, since they heavily rely on the correctness of the labeling. With this experiment, we illustrate that the MSNM approach is coherent with the needs of an incident response team: it provides an adequate priorization of the security events and gives support to diagnosis, so that in less time and with less resources the team can be more effective.
引用
收藏
页码:241 / 246
页数:6
相关论文
共 50 条
  • [21] Preserving authentication and availability security services through Multivariate Statistical Network Monitoring
    Soufiane, Sail
    Magan-Carrion, Roberto
    Medina-Bulo, Inmaculada
    Bouden, Halima
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58
  • [22] IMPROVEMENT OF THE DIMENSION OF AN AIR QUALITY MONITORING NETWORK BY MEANS OF MULTIVARIATE STATISTICAL METHODS
    Doval Minarro, Marta
    Egea, Jose A.
    Navarro Cobacho, Ginesa
    [J]. DYNA, 2020, 95 (02): : 153 - +
  • [23] Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection
    Macia-Fernandez, Gabriel
    Camacho, Jose
    Garcia-Teodoro, Pedro
    Rodriguez-Gomez, Rafael A.
    [J]. 2016 8TH IEEE INTERNATIONAL WORKSHOP ON INFORMATION FORENSICS AND SECURITY (WIFS 2016), 2016,
  • [24] Semi-Supervised Multivariate Statistical Network Monitoring for Learning Security Threats
    Camacho, Jose
    Macia-Fernandez, Gabriel
    Marta Fuentes-Garcia, Noemi
    Saccenti, Edoardo
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (08) : 2179 - 2189
  • [25] Monitoring road traffic congestion using a macroscopic traffic model and a statistical monitoring scheme
    Zerouala, Abdelhafid
    Harrou, Fouzi
    Sun, Ying
    Messai, Nadhir
    [J]. SUSTAINABLE CITIES AND SOCIETY, 2017, 35 : 494 - 510
  • [26] Monitoring network traffic with radial traffic analyzer
    Keim, Daniel A.
    Mansmann, Florian
    Schneidewind, Joern
    Schreck, Tobias
    [J]. VAST 2006: IEEE SYMPOSIUM ON VISUAL ANALYTICS SCIENCE AND TECHNOLOGY, PROCEEDINGS, 2006, : 123 - +
  • [27] MULTIVARIATE STATISTICAL PROCESS MONITORING OF REDUCTION CELLS
    Tessier, Jayson
    Zwirz, Thomas G.
    Tarcy, Gary P.
    Manzini, Richard A.
    [J]. LIGHT METALS 2009, 2009, : 305 - +
  • [28] Multivariate statistical analysis of environmental monitoring data
    Ross, DL
    [J]. GROUND WATER, 1997, 35 (06) : 1050 - 1057
  • [29] New Method for Multivariate Statistical Process Monitoring
    裴旭东
    陈祥光
    刘春涛
    [J]. Journal of Beijing Institute of Technology, 2010, 19 (01) : 92 - 98
  • [30] Multivariate Statistical Monitoring of Wine Ageing Processes
    Pereira, Ana C.
    Reis, Marco S.
    Saraiva, Pedro M.
    Marques, Jose C.
    [J]. 20TH EUROPEAN SYMPOSIUM ON COMPUTER AIDED PROCESS ENGINEERING, 2010, 28 : 247 - 252