On-Line Anomaly Detection With High Accuracy

被引:74
|
作者
Xie, Kun [1 ,2 ,3 ]
Li, Xiaocan [1 ]
Wang, Xin [3 ]
Cao, Jiannong [4 ]
Xie, Gaogang [5 ]
Wen, Jigang [5 ]
Zhang, Dafang [1 ]
Qin, Zheng [1 ]
机构
[1] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410006, Hunan, Peoples R China
[2] Chinese Acad Sci, Inst Comp Technol, CAS Key Lab Network Data Sci & Technol, Beijing, Peoples R China
[3] SUNY Stony Brook, Dept Elect & Comp Engn, Stony Brook, NY 11794 USA
[4] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[5] Chinese Acad Sci, Inst Comp Technol, Network Res Ctr, Beijing 100190, Peoples R China
基金
中国国家自然科学基金; 美国国家科学基金会;
关键词
Anomaly detection; on-line algorithm; bilateral PCA; FACE REPRESENTATION; 2-DIMENSIONAL PCA; PRINCIPAL;
D O I
10.1109/TNET.2018.2819507
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traffic anomaly detection is critical for advanced Internet management. Existing detection algorithms generally convert the high-dimensional data to a long vector, which compromises the detection accuracy due to the loss of spatial information of data. Moreover, they are generally designed based on the separation of normal and anomalous data in a time period, which not only introduces high storage and computation cost but also prevents timely detection of anomalies. Online and accurate traffic anomaly detection is critical but difficult to support. To address the challenge, this paper directly models the monitoring data in each time slot as a 2-D matrix, and detects anomalies in the new time slot based on bilateral principal component analysis (B-PCA). We propose several novel techniques in OnlineBPCA to support quick and accurate anomaly detection in real time, including a novel BPCA-based anomaly detection principle that jointly considers the variation of both row and column principal directions for more accurate anomaly detection, an approximate algorithm to avoid using iteration procedure to calculate the principal directions in a close-form, and a sequential anomaly algorithm to quickly update principal directions with low computation and storage cost when receiving a new data matrix at a time slot. To the best of our knowledge, this is the first work that exploits 2-D PCA for anomaly detection. We have conducted extensive simulations to compare our OnlineBPCA with the state-of-art anomaly detection algorithms using real traffic traces Abilene and GEANT. Our simulation results demonstrate that, compared with other algorithms, our OnlineBPCA can achieve significantly better detection performance with low false positive rate, high true positive rate, and low computation cost.
引用
下载
收藏
页码:1222 / 1235
页数:14
相关论文
共 50 条
  • [41] The on-line slag detection in the steelmaking
    Zahorszki, F
    Lyons, AR
    THERMOSENSE XXII, 2000, 4020 : 10 - 14
  • [42] An approach to on-line predictive detection
    Zhang, F
    Hellerstein, JL
    8TH INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS AND SIMULATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS, PROCEEDINGS, 2000, : 549 - 556
  • [43] On-line bacteriological detection in water
    Lopez-Roldan, Ramon
    Tusell, Pol
    Courtois, Sophie
    Luis Cortina, Jose
    TRAC-TRENDS IN ANALYTICAL CHEMISTRY, 2013, 44 : 46 - 57
  • [44] Improving the accuracy of on-line melt index measurements
    Nelson, BI
    CONFERENCE PROCEEDINGS AT ANTEC '98: PLASTICS ON MY MIND, VOLS I-3: VOL I; PROCESSING, VOL II; SPECIAL AREAS, VOL III; MATERIALS, 1998, 44 : 924 - 928
  • [45] Efficient on-line repetition detection
    Hong, Jin-Ju
    Chen, Gen-Huey
    THEORETICAL COMPUTER SCIENCE, 2008, 407 (1-3) : 554 - 563
  • [46] On-line detection of winding deformation
    Alpatov, M
    CONFERENCE RECORD OF THE 2004 IEEE INTERNATIONAL SYMPOSIUM ON ELECTRICAL INSULATION, 2004, : 113 - 116
  • [47] Interval Differentiators: on-line estimation of differentiation accuracy
    Guerra, Matteo
    Vazquez, Carlos
    Efimov, Denis
    Zheng, Gang
    Freidovich, Leonid
    Perruquetti, Wilfrid
    2016 EUROPEAN CONTROL CONFERENCE (ECC), 2016, : 1347 - 1352
  • [48] Accuracy of on-line databases in determining vital status
    Hauser, TH
    Ho, KKL
    JOURNAL OF CLINICAL EPIDEMIOLOGY, 2001, 54 (12) : 1267 - 1270
  • [49] Methodology for increasing accuracy of on-line insulation diagnosis
    Huang, XH
    Gao, WS
    Yan, Z
    JOINT CONFERENCE OF 96' AICDEI / 4T-JCCEID, 1996, : 333 - 336
  • [50] The Current Transformer Accuracy On-Line Evaluation System
    Yan Dong
    Xie Kai
    Wang Yong
    Yang Xiao-Hui
    Ma Fei
    Qiao Li-Hong
    MATERIALS SCIENCE AND INFORMATION TECHNOLOGY, PTS 1-8, 2012, 433-440 : 6880 - +