Comparison of Supervised and Unsupervised Learning for Detecting Anomalies in Network Traffic

被引:0
|
作者
McAndrew, Robert [1 ]
Hayne, Stephen [1 ]
Wang, Haonan [1 ]
机构
[1] Colorado State Univ, Ft Collins, CO 80523 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Adversaries are always probing for vulnerable spots on the Internet so they can attack their target. By examining traffic at the firewall, we can look for anomalies that may represent these probes. To help select the right techniques we conduct comparisons of supervised and unsupervised machine learning on network flows to find sets of outliers flagged as potential threats. We apply Functional PCA and K-Means together versus Multilayer Perceptron on a real-world dataset of traffic prior to an NTP DDoS attack in January 2014; scanning activity was heightened during this pre-attack period. We partition data to evaluate detection powers of each technique and show that FPCA+Kmeans outperforms MLP. We also present a new variation of the circle plot for visualization of resulting outliers which we suggest excels at displaying multidimensional attributes of an individual IP's behavior over time. In small multiples, circle plots show a gestalt overview of traffic.
引用
收藏
页码:7136 / 7145
页数:10
相关论文
共 50 条
  • [31] A Hybrid Classification Approach of Network Attacks using Supervised and Unsupervised Learning
    Al-Ruwaili, Rahaf Hamoud R.
    Ouda, Osama M.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (08) : 818 - 828
  • [32] Design on supervised/unsupervised learning reconfigurable digital neural network structure
    Yu, In Gab
    Lee, Yong Min
    Ye, Seong Won
    Lee, Chong Ho
    PRICAI 2006: TRENDS IN ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2006, 4099 : 1201 - 1205
  • [33] Anomalies in Network Traffic
    Ratner, Alan S.
    Kelly, Phillip
    2013 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS: BIG DATA, EMERGENT THREATS, AND DECISION-MAKING IN SECURITY INFORMATICS, 2013, : 206 - 208
  • [34] A wavelet-based neural network scheme for supervised and unsupervised learning
    Esquivel, Manuel L.
    Krasii, Nadezhda P.
    NEURAL COMPUTING & APPLICATIONS, 2021, 33 (20): : 13433 - 13448
  • [35] A wavelet-based neural network scheme for supervised and unsupervised learning
    Manuel L. Esquível
    Nadezhda P. Krasii
    Neural Computing and Applications, 2021, 33 : 13433 - 13448
  • [36] Detecting Abnormal Event in Traffic Scenes using Unsupervised Deep Learning Approach
    Meena, K.
    Viji, A.
    Athanesious, J. Joshan
    Vaidehi, V.
    2019 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET 2019): ADVANCING WIRELESS AND MOBILE COMMUNICATIONS TECHNOLOGIES FOR 2020 INFORMATION SOCIETY, 2019, : 355 - 362
  • [37] Supervised extended ART: A fast neural network classifier trained by combining supervised and unsupervised learning
    Lee, HM
    Lai, CS
    APPLIED INTELLIGENCE, 1996, 6 (02) : 117 - 128
  • [38] Detecting 5G Signal Jammers Using Spectrograms with Supervised and Unsupervised Learning
    Varotto, Matteo
    Valentin, Stefan
    Tomasin, Stefano
    2024 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS 2024, 2024, : 767 - 772
  • [39] Ensembling Supervised and Unsupervised Machine Learning Algorithms for Detecting Distributed Denial of Service Attacks
    Das, Saikat
    Ashrafuzzaman, Mohammad
    Sheldon, Frederick T.
    Shiva, Sajjan
    ALGORITHMS, 2024, 17 (03)
  • [40] Detecting traffic anomalies with adaptive sampling
    Pele, Liat
    Buczko, Udi
    Galor, Oren
    Israel, Nokia
    Einziger, Gil
    SYSTOR '19: PROCEEDINGS OF THE 12TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE, 2019, : 186 - 186