Detecting anomalies in backbone network traffic: a performance comparison among several change detection methods

被引:0
|
作者
Callegari, Christian [1 ]
Giordano, Stefano [1 ]
Pagano, Michele [1 ]
Pepe, Teresa [1 ]
机构
[1] Univ Pisa, Dept Informat Engn, Pisa, Italy
关键词
anomaly detection; reversible sketch; heavy hitter; heavy change; multi-chart non-parametric CUSUM algorithm; ALGORITHMS; ATTACKS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the last years, the ever increasing number of network attacks has brought the research attention to the design and development of effective anomaly detection systems. To this aim, the main target is to develop efficient algorithms able to detect abrupt changes in the data, with the smallest detection delay. In this paper, we present a novel method for network anomaly detection, based on the idea of discovering heavy change (HC) in the distribution of the Heavy I-litters in the network traffic, by applying several forecasting algorithms. To assess the validity of the proposed method, we have performed an experimental evaluation phase, during which our system performance have been compared to more 'classical' approaches, such as a standard HC method and the promising CUSUM method. The performance analysis, presented in this paper, demonstrates the effectiveness of the proposed method, showing how it is able to outperform the 'classical' approaches.
引用
收藏
页码:205 / 214
页数:10
相关论文
共 32 条
  • [1] Detecting Heavy Change in the Heavy Hitter Distribution of Network Traffic
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    Pepe, Teresa
    2011 7TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2011, : 1298 - 1303
  • [2] Detecting anomalies from big network traffic data using an adaptive detection approach
    Zhang, Ji
    Li, Hongzhou
    Gao, Qigang
    Wang, Hai
    Luo, Yonglong
    INFORMATION SCIENCES, 2015, 318 : 91 - 110
  • [3] Detecting anomalies and attacks in network traffic monitoring with classification methods and XAI-based explainability
    Wawrowski, Lukasz
    Michalak, Marcin
    Bialas, Andrzej
    Kurianowicz, Rafal
    Sikora, Marek
    Uchronski, Mariusz
    Kajzer, Adrian
    KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS (KSE 2021), 2021, 192 : 2259 - 2268
  • [4] Detecting Anomalies in Network Traffic Using the Method of Remaining Elements
    Velarde-Alvarado, P.
    Vargas-Rosales, C.
    Torres-Roman, D.
    Martinez-Heffera, A.
    IEEE COMMUNICATIONS LETTERS, 2009, 13 (06) : 462 - 462
  • [5] On the Detection of Network Traffic Anomalies in Content Delivery Network Services
    Fiadino, Pierdomenico
    D'Alconzo, Alessandro
    Baer, Arian
    Finamore, Alessandro
    Casas, Pedro
    2014 26TH INTERNATIONAL TELETRAFFIC CONGRESS (ITC), 2014,
  • [6] Improvement the schemes and models of detecting network traffic anomalies on computer systems
    Yusupdjanovich, Yusupov Sabirjan
    Rajaboevich, Gulomov Sherzod
    2020 IEEE 14TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT2020), 2020,
  • [7] HADOOP-BASED NETWORK TRAFFIC ANOMALY DETECTION IN BACKBONE
    Yu, Jishen
    Liu, Feng
    Zhou, Wenli
    Yu, Hua
    2014 IEEE 3rd International Conference on Cloud Computing and Intelligence Systems (CCIS), 2014, : 140 - 145
  • [8] A Traffic Decomposition and Prediction Method for Detecting and Tracing Network-Wide Anomalies
    Du, Ping
    Abe, Shunji
    Ji, Yusheng
    Sato, Seisho
    Ishiguro, Makio
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2009, E92D (05) : 929 - 936
  • [9] Why Did the Shape of Your Network Change? (On Detecting Network Anomalies via Non-local Curvatures)
    DasGupta, Bhaskar
    Janardhanan, Mano Vikash
    Yahyanejad, Farzane
    ALGORITHMICA, 2020, 82 (07) : 1741 - 1783
  • [10] An information-theoretic method for the detection of anomalies in network traffic
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    COMPUTERS & SECURITY, 2017, 70 : 351 - 365