Online Adaptive Anomaly Detection for Augmented Network Flows

被引:13
|
作者
Ippoliti, Dennis [2 ]
Jiang, Changjun [3 ]
Ding, Zhijun [3 ]
Zhou, Xiaobo [1 ]
机构
[1] Univ Colorado, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[2] Dept Comp Sci, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918 USA
[3] Tongji Univ, 4800 Caoan Rd, Shanghai 201804, Peoples R China
关键词
Flow-based anomaly detection; online adaptation; support vector machine; dynamic input normalization; Design; Experimentation; Performance; Security;
D O I
10.1145/2934686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Traditional network anomaly detection involves developing models that rely on packet inspection. However, increasing network speeds and use of encrypted protocols make per-packet inspection unsuited for today's networks. One method of overcoming this obstacle is aggregating packet header information and performing flow-based analysis where data flow patterns are examined rather than deep packet inspection. Many existing approaches are special purpose limited to detecting specific behavior. Also, the data reduction inherent in identifying anomalous flows hinders alert correlation. In this article, we propose and develop a dynamic anomaly detection approach for augmented network flows. We sketch network state during flow creation, enabling general-purpose threat detection. We describe an efficient flow augmentation approach based on the count-min sketch that provides per-flow-, per-node-, and per-network-level statistics parallel to flow record generation. We design and develop a support vector machine-based adaptive anomaly detection and correlation mechanism, which is capable of aggregating alerts without a priori alert classification and evolving models online. We further develop a lightweight evolving alert aggregation method and combine it with a confidence forwarding mechanism identifying a small percentage predictions for additional processing. We show effectiveness of our methods on both enterprise and backbone traces. Experimental results demonstrate its ability to maintain high accuracy without the need for offline training.
引用
收藏
页数:28
相关论文
共 50 条
  • [41] Memory-Augmented Spatial-Temporal Consistency Network for Video Anomaly Detection
    Li, Zhangxun
    Zhao, Mengyang
    Zeng, Xinhua
    Wang, Tian
    Pang, Chengxin
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT VI, 2024, 14430 : 95 - 107
  • [42] NEW ADAPTIVE NETWORK ANOMALY DETECTION SYSTEM USING FREQUENT PATTERNS
    Said, Aiman Moyaid
    Dominic, Dhanapal Durai
    Samir, Brahim Belhaouari
    Balfagih, Zain
    4TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGY AND ENGINEERING (ICSTE 2012), 2012, : 369 - 374
  • [43] Fairness based on anomaly score and adaptive weight in network attack detection
    Wen, Xuezhi
    Gao, Meiqi
    Wang, Nan
    Ma, Jiahui
    Zhang, Dalin
    Zhao, Xibin
    Liu, Jiqiang
    INFORMATION SCIENCES, 2024, 678
  • [44] A multi-memory-augmented network with a curvy metric method for video anomaly detection
    Li, Hongjun
    Wang, Yunlong
    Wang, Yating
    Chen, Junjie
    NEURAL NETWORKS, 2025, 184
  • [45] Adaptive Monte Carlo augmented with normalizing flows
    Gabrie, Marylou
    Rotskoff, Grant M.
    Vanden-Eijnden, Eric
    PROCEEDINGS OF THE NATIONAL ACADEMY OF SCIENCES OF THE UNITED STATES OF AMERICA, 2022, 119 (10)
  • [46] Memory-Augmented Autoencoder With Adaptive Reconstruction and Sample Attribution Mining for Hyperspectral Anomaly Detection
    Huo, Yu
    Cheng, Xi
    Lin, Sheng
    Zhang, Min
    Wang, Hai
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 18
  • [47] Quantum normalizing flows for anomaly detection
    Rosenhahn, Bodo
    Hirche, Christoph
    PHYSICAL REVIEW A, 2024, 110 (02)
  • [48] Unsupervised Anomaly Detection with a GAN Augmented Autoencoder
    Rafiee, Laya
    Fevens, Thomas
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2020, PT I, 2020, 12396 : 479 - 490
  • [49] A lightweight online network anomaly detection scheme based on date mining methods
    Li, Yang
    Fang, Bin-Xing
    2007 IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS, 2007, : 340 - 341
  • [50] Online Data-Centric Anomaly Detection Framework For Sensor Network Deployments
    Abuaitah, Giovani Rimon
    Wang, Bin
    2014 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2014, : 599 - 604