Predictive Network Anomaly Detection and Visualization

被引:23
|
作者
Celenk, Mehmet [1 ]
Conley, Thomas [1 ]
Willis, John [1 ]
Graham, James [1 ]
机构
[1] Ohio Univ, Sch Elect Engn & Comp Sci, Stocker Ctr, Athens, OH 45701 USA
关键词
Auto-regressive moving average (ARMA) modeling; entropy; Fisher discriminant; network anomaly; Wiener filtering; TRAFFIC ANOMALIES; PERIODOGRAM;
D O I
10.1109/TIFS.2010.2041808
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Various approaches have been developed for quantifying and displaying network traffic information for determining network status and in detecting anomalies. Although many of these methods are effective, they rely on the collection of long-term network statistics. Here, we present an approach that uses short-term observations of network features and their respective time averaged entropies. Acute changes are localized in network feature space using adaptive Wiener filtering and auto-regressive moving average modeling. The color-enhanced datagram is designed to allow a network engineer to quickly capture and visually comprehend at a glance the statistical characteristics of a network anomaly. First, average entropy for each feature is calculated for every second of observation. Then, the resultant short-term measurement is subjected to first-and second-order time averaging statistics. These measurements are the basis of a novel approach to anomaly estimation based on the well-known Fisher linear discriminant (FLD). Average port, high port, server ports, and peered ports are some of the network features used for stochastic clustering and filtering. We empirically determine that these network features obey Gaussian-like distributions. The proposed algorithm is tested on real-time network traffic data from Ohio University's main Internet connection. Experimentation has shown that the presented FLD-based scheme is accurate in identifying anomalies in network feature space, in localizing anomalies in network traffic flow, and in helping network engineers to prevent potential hazards. Furthermore, its performance is highly effective in providing a colorized visualization chart to network analysts in the presence of bursty network traffic.
引用
收藏
页码:288 / 299
页数:12
相关论文
共 50 条
  • [1] A Tri-Linear Visualization for Network Anomaly Detection
    Whitaker, Robert B.
    Erbacher, Robert F.
    [J]. VISUALIZATION AND DATA ANALYSIS 2011, 2011, 7868
  • [2] A survey of network anomaly visualization
    Tianye ZHANG
    Xumeng WANG
    Zongzhuang LI
    Fangzhou GUO
    Yuxin MA
    Wei CHEN
    [J]. Science China(Information Sciences), 2017, 60 (12) : 126 - 142
  • [3] A survey of network anomaly visualization
    Tianye Zhang
    Xumeng Wang
    Zongzhuang Li
    Fangzhou Guo
    Yuxin Ma
    Wei Chen
    [J]. Science China Information Sciences, 2017, 60
  • [4] A survey of network anomaly visualization
    Zhang, Tianye
    Wang, Xumeng
    Li, Zongzhuang
    Guo, Fangzhou
    Ma, Yuxin
    Chen, Wei
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2017, 60 (12)
  • [5] Bridging the Gap of Network Management and Anomaly Detection through Interactive Visualization
    Zhang, Tao
    Liao, Qi
    Shi, Lei
    [J]. 2014 IEEE Pacific Visualization Symposium (PacificVis), 2014, : 253 - 257
  • [6] Anomaly Detection and Visualization using Fisher Discriminant Clustering of Network Entropy
    Celenk, Mehmet
    Conley, Thomas
    Willis, John
    Graham, James
    [J]. 2008 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION MANAGEMENT, VOLS 1 AND 2, 2008, : 219 - 223
  • [7] Visualization of Data Cubes for Anomaly Detection in Network Traffic Data Streams
    Ahlers, Volker
    Laue, Tim
    Wellermann, Nils
    Heine, Felix
    [J]. PROCEEDINGS OF THE THE 11TH IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS'2021), VOL 1, 2021, : 272 - 277
  • [8] AnoPCN: Video Anomaly Detection via Deep Predictive Coding Network
    Ye, Muchao
    Peng, Xiaojiang
    Gan, Weihao
    Wu, Wei
    Qiao, Yu
    [J]. PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA (MM'19), 2019, : 1805 - 1813
  • [9] Visualization for Anomaly Detection and Data Management by Leveraging Network, Sensor and GIS techniques
    Wang, Zhaoxia
    Chong, Chee Seng
    Goh, Rick Siow Mong
    Zhou, Wanqing
    Peng, Dan
    Chin, Hoong Chor
    [J]. PROCEEDINGS OF THE 2012 IEEE 18TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS 2012), 2012, : 907 - 912
  • [10] Internet routing anomaly detection and visualization
    Wong, T
    Jacobson, V
    Alaettinoglu, C
    [J]. 2005 INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2005, : 172 - 181