A Hybrid Model for BGP Anomaly Detection Using Median Absolute Deviation and Machine Learning

被引:0
作者
Romo-Chavero, Maria Andrea [1 ]
Alatorre, Gustavo De Los Rios
Cantoral-Ceballos, Jose Antonio [1 ]
Perez-Diaz, Jesus Arturo [1 ]
Martinez-Cagnazzo, Carlos
机构
[1] Tecnol Monterrey, Sch Engn & Sci, Monterrey 64849, Mexico
来源
IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY | 2025年 / 6卷
关键词
Anomaly detection; border gateway protocol; machine learning; median absolute deviation; statistics;
D O I
10.1109/OJCOMS.2025.3550010
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Detecting anomalies in the Border Gateway Protocol (BGP) has proved relevant in the cybersecurity field due to the protocol's critical role in the Internet's infrastructure. BGP vulnerabilities can lead to major disruptions and connectivity failures, highlighting the need for early detection to maintain stable and secure Internet services. To address this challenge, our article presents an enhanced version of our previously published Median Absolute Deviation (MAD) anomaly detection system. We introduce a novel dynamic threshold mechanism that significantly enhances anomaly detection performance in BGP, achieving superior accuracy and F1-score. Through a comparative analysis of machine learning (ML) classification models-including Random Forest, Extra Trees, XGBoost, LightGBM, and CatBoost-we demonstrate that integrating our MAD detection system with these ML models can improve anomaly detection significantly. Additionally, we explore how MAD performs when combined with neural networks such as RNN, GRU, and LSTM, providing a valuable comparison between machine learning and neural network-based approaches. We evaluate the models performance in well-known events, such as CodeRed 1 v2, Slammer, Nimda, the Moscow blackout, and the Telekom Malaysia (TMnet) misconfiguration. Our results show an overall accuracy of 0.99 and F1-score of 0.98, demonstrating the effective integration of MAD and ML models for the identification of security threats. Our approach enables proactive detection with minimal computational costs and reduced preprocessing, proving that efficient anomaly detection is achievable.
引用
收藏
页码:2102 / 2116
页数:15
相关论文
共 50 条
  • [41] A Hybrid Reinforcement Learning Model used for Anomaly Detection
    Lu, Tsung-Hui
    Chen, Chun-Te
    BASIC & CLINICAL PHARMACOLOGY & TOXICOLOGY, 2020, 127 : 82 - 83
  • [42] Efficient BGP Intrusion Detection Model Using Machine Learning: A Comparative Study with AdaBoost as the Optimal Classifier
    Abdoun, Manaf
    Guennoun, Mouhcine
    Amar, Amine
    Saad, Tarek
    Taha, Mostafa
    2023 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, CCECE, 2023,
  • [43] Hybrid Anomaly Detection in Time Series by Combining Kalman Filters and Machine Learning Models
    Puder, Andreas
    Zink, Moritz
    Seidel, Luca
    Sax, Eric
    SENSORS, 2024, 24 (09)
  • [44] IP Network Anomaly Detection using Machine Learning
    Nair, Roshan
    Kasula, Chaithanya Pramodh
    Vankayala, Sravanthi
    Chakraborty, Niloy
    2019 IEEE 5TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2019,
  • [45] Machine Learning in Network Anomaly Detection: A Survey
    Wang, Song
    Balarezo, Juan Fernando
    Kandeepan, Sithamparanathan
    Al-Hourani, Akram
    Chavez, Karina Gomez
    Rubinstein, Benjamin
    IEEE ACCESS, 2021, 9 : 152379 - 152396
  • [46] Machine Learning Approaches to Maritime Anomaly Detection
    Obradovic, Ines
    Milicevic, Mario
    Zubrinic, Krunoslav
    NASE MORE, 2014, 61 (5-6): : 96 - 101
  • [47] Machine Learning for Anomaly Detection: A Systematic Review
    Nassif, Ali Bou
    Talib, Manar Abu
    Nasir, Qassim
    Dakalbab, Fatima Mohamad
    IEEE ACCESS, 2021, 9 : 78658 - 78700
  • [48] Machine Learning Anomaly Detection in Large Systems
    Murphree, Jerry
    2016 IEEE AUTOTESTCON PROCEEDINGS, 2016,
  • [49] Detecting BGP Routing Anomalies Using Machine Learning: A Review
    Muosa, Ali Hassan
    Ali, A. H.
    FORTHCOMING NETWORKS AND SUSTAINABILITY IN THE AIOT ERA, VOL 1, FONES-AIOT 2024, 2024, 1035 : 145 - 164
  • [50] INTELLIGENT ANOMALY DETECTION MODEL FOR ATM BOOTH SURVEILLANCE USING MACHINE LEARNING ALGORITHM
    Viji, S.
    Kannan, R.
    Jayalashmi, N. Yogambal
    2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, AND INTELLIGENT SYSTEMS (ICCCIS), 2021, : 1007 - 1012