Online Adaptive Anomaly Detection for Augmented Network Flows

被引:13
|
作者
Ippoliti, Dennis [2 ]
Jiang, Changjun [3 ]
Ding, Zhijun [3 ]
Zhou, Xiaobo [1 ]
机构
[1] Univ Colorado, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[2] Dept Comp Sci, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[3] Tongji Univ, 4800 Caoan Rd, Shanghai 201804, Peoples R China
关键词
Flow-based anomaly detection; online adaptation; support vector machine; dynamic input normalization; Design; Experimentation; Performance; Security;
D O I
10.1145/2934686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Traditional network anomaly detection involves developing models that rely on packet inspection. However, increasing network speeds and use of encrypted protocols make per-packet inspection unsuited for today's networks. One method of overcoming this obstacle is aggregating packet header information and performing flow-based analysis where data flow patterns are examined rather than deep packet inspection. Many existing approaches are special purpose limited to detecting specific behavior. Also, the data reduction inherent in identifying anomalous flows hinders alert correlation. In this article, we propose and develop a dynamic anomaly detection approach for augmented network flows. We sketch network state during flow creation, enabling general-purpose threat detection. We describe an efficient flow augmentation approach based on the count-min sketch that provides per-flow-, per-node-, and per-network-level statistics parallel to flow record generation. We design and develop a support vector machine-based adaptive anomaly detection and correlation mechanism, which is capable of aggregating alerts without a priori alert classification and evolving models online. We further develop a lightweight evolving alert aggregation method and combine it with a confidence forwarding mechanism identifying a small percentage predictions for additional processing. We show effectiveness of our methods on both enterprise and backbone traces. Experimental results demonstrate its ability to maintain high accuracy without the need for offline training.
引用
收藏
页数:28
相关论文
共 50 条
  • [21] Augmented Time Regularized Generative Adversarial Network (ATR-GAN) for Data Augmentation in Online Process Anomaly Detection
    Li, Yuxuan
    Shi, Zhangyue
    Liu, Chenang
    Tian, Wenmeng
    Kong, Zhenyu
    Williams, Christopher B.
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2022, 19 (04) : 3338 - 3355
  • [22] Network Anomaly Detection Using Memory-Augmented Deep Autoencoder
    Min, Byeongjun
    Yoo, Jihoon
    Kim, Sangsoo
    Shin, Dongil
    Shin, Dongkyoo
    IEEE ACCESS, 2021, 9 : 104695 - 104706
  • [23] Online Detection of Anomalous Network Flows with Soft Clustering
    Zolotukhin, Mikhail
    Hamalainen, Timo
    Kokkonen, Tero
    Siltanen, Jarmo
    2015 7TH INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2015,
  • [24] Tiresias: Online Anomaly Detection for Hierarchical Operational Network Data
    Hong, Chi-Yao
    Caesar, Matthew
    Duffield, Nick
    Wang, Jia
    2012 IEEE 32ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2012, : 173 - 182
  • [25] Tensor-Based Online Network Anomaly Detection and Diagnosis
    Shajari, Mehdi
    Geng, Hongxiang
    Hu, Kaixuan
    Leon-Garcia, Alberto
    IEEE ACCESS, 2022, 10 : 85792 - 85817
  • [26] Unsupervised online anomaly detection in Software Defined Network environments
    Scaranti, Gustavo Frigo
    Carvalho, Luiz Fernando
    Barbon, Sylvio
    Lloret, Jaime
    Proenca, Mario Lemes
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 191
  • [27] Distributed Online Anomaly Detection for Virtualized Network Slicing Environment
    Wang, Weili
    Liang, Chengchao
    Chen, Qianbin
    Tang, Lun
    Yanikomeroglu, Halim
    Liu, Tong
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2022, 71 (11) : 12235 - 12249
  • [28] Tensor-Based Online Network Anomaly Detection and Diagnosis
    Shajari, Mehdi
    Geng, Hongxiang
    Hu, Kaixuan
    Leon-Garcia, Alberto
    IEEE Access, 2022, 10 : 85792 - 85817
  • [29] Adaptive Performance Anomaly Detection in Distributed Systems Using Online SVMs
    Alvarez Cid-Fuentes, Javier
    Szabo, Claudia
    Falkner, Katrina
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2020, 17 (05) : 928 - 941
  • [30] Robust Variational Autoencoders and Normalizing Flows for Unsupervised Network Anomaly Detection
    Najari, Naji
    Berlemont, Samuel
    Lefebvre, Gregoire
    Duffner, Stefan
    Garcia, Christophe
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 281 - 292