A Hybrid Model for BGP Anomaly Detection Using Median Absolute Deviation and Machine Learning

被引:0
作者
Romo-Chavero, Maria Andrea [1 ]
Alatorre, Gustavo De Los Rios
Cantoral-Ceballos, Jose Antonio [1 ]
Perez-Diaz, Jesus Arturo [1 ]
Martinez-Cagnazzo, Carlos
机构
[1] Tecnol Monterrey, Sch Engn & Sci, Monterrey 64849, Mexico
来源
IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY | 2025年 / 6卷
关键词
Anomaly detection; border gateway protocol; machine learning; median absolute deviation; statistics;
D O I
10.1109/OJCOMS.2025.3550010
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Detecting anomalies in the Border Gateway Protocol (BGP) has proved relevant in the cybersecurity field due to the protocol's critical role in the Internet's infrastructure. BGP vulnerabilities can lead to major disruptions and connectivity failures, highlighting the need for early detection to maintain stable and secure Internet services. To address this challenge, our article presents an enhanced version of our previously published Median Absolute Deviation (MAD) anomaly detection system. We introduce a novel dynamic threshold mechanism that significantly enhances anomaly detection performance in BGP, achieving superior accuracy and F1-score. Through a comparative analysis of machine learning (ML) classification models-including Random Forest, Extra Trees, XGBoost, LightGBM, and CatBoost-we demonstrate that integrating our MAD detection system with these ML models can improve anomaly detection significantly. Additionally, we explore how MAD performs when combined with neural networks such as RNN, GRU, and LSTM, providing a valuable comparison between machine learning and neural network-based approaches. We evaluate the models performance in well-known events, such as CodeRed 1 v2, Slammer, Nimda, the Moscow blackout, and the Telekom Malaysia (TMnet) misconfiguration. Our results show an overall accuracy of 0.99 and F1-score of 0.98, demonstrating the effective integration of MAD and ML models for the identification of security threats. Our approach enables proactive detection with minimal computational costs and reduced preprocessing, proving that efficient anomaly detection is achievable.
引用
收藏
页码:2102 / 2116
页数:15
相关论文
共 50 条
  • [31] Anomaly detection for atomic clocks using unsupervised machine learning algorithms
    Chen, Edwin
    Charbonneau, Andre
    Gertsvolf, Marina
    Wang, Yunli
    METROLOGIA, 2024, 61 (05)
  • [32] Simulation and Modeling for Anomaly Detection in IoT Network Using Machine Learning
    Mukherjee, Indrajit
    Sahu, Nilesh Kumar
    Sahana, Sudip Kumar
    INTERNATIONAL JOURNAL OF WIRELESS INFORMATION NETWORKS, 2023, 30 (02) : 173 - 189
  • [33] Wireless Sensor Networks Anomaly Detection Using Machine Learning: A Survey
    Haque, Ahshanul
    Chowdhury, Naseef-Ur-Rahman
    Soliman, Hamdy
    Hossen, Mohammad Sahinur
    Fatima, Tanjim
    Ahmed, Imtiaz
    INTELLIGENT SYSTEMS AND APPLICATIONS, VOL 3, INTELLISYS 2023, 2024, 824 : 491 - 506
  • [34] Anomaly detection in wireless sensor network using machine learning algorithm
    Poornima, I. Gethzi Ahila
    Paramasivan, B.
    COMPUTER COMMUNICATIONS, 2020, 151 : 331 - 337
  • [35] Anomaly Detection in Network Traffic Using Advanced Machine Learning Techniques
    Ness, Stephanie
    Eswarakrishnan, Vishwanath
    Sridharan, Harish
    Shinde, Varun
    Janapareddy, Naga Venkata Prasad
    Dhanawat, Vineet
    IEEE ACCESS, 2025, 13 : 16133 - 16149
  • [36] Anomaly Detection Using Smart Shirt and Machine Learning: A Systematic Review
    Nunes, E. C.
    Barbosa, Jose
    Alves, Paulo
    Franco, Tiago
    Silva, Alfredo
    OPTIMIZATION, LEARNING ALGORITHMS AND APPLICATIONS, OL2A 2022, 2022, 1754 : 470 - 485
  • [37] Simulation and Modeling for Anomaly Detection in IoT Network Using Machine Learning
    Indrajit Mukherjee
    Nilesh Kumar Sahu
    Sudip Kumar Sahana
    International Journal of Wireless Information Networks, 2023, 30 : 173 - 189
  • [38] A machine learning framework for network anomaly detection using SVM and GA
    Shon, T
    Kim, Y
    Lee, C
    Moon, A
    PROCEEDINGS FROM THE SIXTH ANNUAL IEEE SYSTEMS, MAN AND CYBERNETICS INFORMATION ASSURANCE WORKSHOP, 2005, : 176 - 183
  • [39] ANOMALY DETECTION IN THE TEMPERATURE OF AN AC MOTOR USING EMBEDDED MACHINE LEARNING
    Ismail, Ezzeldin Ayman Ibrahim
    Ahmad, Mohd Ridzuan
    JURNAL TEKNOLOGI-SCIENCES & ENGINEERING, 2023, 85 (06): : 67 - 73
  • [40] Feature Reduction and Anomaly Detection in IoT Using Machine Learning Algorithms
    Hamdan, Adel
    Tahboush, Muhannad
    Adawy, Mohammad
    Alwada'n, Tariq
    Ghwanmeh, Sameh
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2025, 16 (01) : 463 - 470