Improving PCA-based anomaly detection by using multiple time scale analysis and Kullback-Leibler divergence

被引:21
|
作者
Callegari, Christian [1 ]
Gazzarrini, Loris [1 ]
Giordano, Stefano [1 ]
Pagano, Michele [1 ]
Pepe, Teresa [1 ]
机构
[1] Univ Pisa, Dept Informat Engn, Pisa, Italy
关键词
anomaly detection; K-L divergence; multiple time scale; PCA; INTRUSION DETECTION;
D O I
10.1002/dac.2432
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The increasing number of network attacks causes growing problems for network operators and users. Thus, detecting anomalous traffic is of primary interest in IP networks management. In this paper, we address the problem considering a method based on PCA for detecting network anomalies. In more detail, this paper presents a new technique that extends the state of the art in PCA-based anomaly detection. Indeed, by means of multi-scale analysis and Kullback-Leibler divergence, we are able to obtain great improvements with respect to the performance of the 'classical' approach. Moreover, we also introduce a method for identifying the flows responsible for an anomaly detected at the aggregated level. The performance analysis, presented in this paper, demonstrates the effectiveness of the proposed method. Copyright (C) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1731 / 1751
页数:21
相关论文
共 50 条
  • [1] Anomaly Detection Using the Kullback-Leibler Divergence Metric
    Afgani, Mostafa
    Sinanovic, Sinan
    Haas, Harald
    ISABEL: 2008 FIRST INTERNATIONAL SYMPOSIUM ON APPLIED SCIENCES IN BIOMEDICAL AND COMMMUNICATION TECHNOLOGIES, 2008, : 197 - 201
  • [2] Kullback-Leibler Divergence (KLD) Based Anomaly Detection and Monotonic Sequence Analysis
    Anderson, Alan
    Haas, Harald
    2011 IEEE VEHICULAR TECHNOLOGY CONFERENCE (VTC FALL), 2011,
  • [3] Anomaly detection based on probability density function with Kullback-Leibler divergence
    Wang, Wei
    Zhang, Baoju
    Wang, Dan
    Jiang, Yu
    Qin, Shan
    SIGNAL PROCESSING, 2016, 126 : 12 - 17
  • [4] Damage detection using the improved Kullback-Leibler divergence
    Tian, Shaohua
    Chen, Xuefeng
    Yang, Zhibo
    He, Zhengjia
    Zhang, Xingwu
    STRUCTURAL ENGINEERING AND MECHANICS, 2013, 48 (03) : 291 - 308
  • [5] Android Malware Detection Using Kullback-Leibler Divergence
    Cooper, Vanessa N.
    Haddad, Hisham M.
    Shahriar, Hossain
    ADCAIJ-ADVANCES IN DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE JOURNAL, 2014, 3 (02): : 17 - 24
  • [6] Hardware Implementation of a Kullback-Leibler Divergence Based Signal Anomaly Detector
    Afgani, Mostafa
    Sinanovic, Sinan
    Haas, Harald
    2009 2ND INTERNATIONAL SYMPOSIUM ON APPLIED SCIENCES IN BIOMEDICAL AND COMMUNICATION TECHNOLOGIES (ISABEL 2009), 2009, : 517 - 522
  • [7] Fault detection in dynamic systems using the Kullback-Leibler divergence
    Xie, Lei
    Zeng, Jiusun
    Kruger, Uwe
    Wang, Xun
    Geluk, Jaap
    CONTROL ENGINEERING PRACTICE, 2015, 43 : 39 - 48
  • [8] Faults diagnosis and detection using Principal Component Analysis and Kullback-Leibler Divergence
    Harmouche, Jinane
    Delpha, Claude
    Diallo, Demba
    38TH ANNUAL CONFERENCE ON IEEE INDUSTRIAL ELECTRONICS SOCIETY (IECON 2012), 2012, : 3907 - 3912
  • [9] Local inconsistency detection using the Kullback-Leibler divergence measure
    Spineli, Loukia M.
    SYSTEMATIC REVIEWS, 2024, 13 (01)
  • [10] Biological Data Outlier Detection Based on Kullback-Leibler Divergence
    Oh, Jung Hun
    Gao, Jean
    Rosenblatt, Kevin
    2008 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE, PROCEEDINGS, 2008, : 249 - +