Improving network anomaly detection via selective flow-based sampling

被引:33
作者
Androulidakis, G. [1 ]
Papavassiliou, S. [1 ]
机构
[1] Natl Tech Univ Athens, Sch Elect & Comp Engn, Network Management & Optimal Design Lab NETMODE, Athens 15780, Greece
关键词
D O I
10.1049/iet-com:20070231
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Sampling has become an essential component of scalable Internet traffic monitoring and anomaly detection. A new flow- based sampling technique that focuses on the selection of small flows, which are usually the source of malicious traffic, is introduced and analysed. The proposed approach provides a flexible framework for preferential flow sampling that can effectively balance the tradeoff between the volume of the processed information and the anomaly detection accuracy. The performance evaluation of the impact of selective flow- based sampling on the anomaly detection process is achieved through the adoption and application of a sequential non- parametric change- point anomaly detection method on realistic data that have been collected from a real operational university campus network. The corresponding numerical results demonstrate that the proposed approach achieves to improve anomaly detection effectiveness and at the same time reduces the number of selected flows.
引用
收藏
页码:399 / 409
页数:11
相关论文
共 23 条
[1]  
ANDROULIDAKIS G., 2006, IEEE MIL COMM C WASH
[2]  
[Anonymous], 2003, PREDICTING RESOURCE, DOI [10.1145/948205.948228, DOI 10.1145/948205.948228]
[3]  
[Anonymous], 2006, IMC 06 P 6 ACM SIGCO, DOI DOI 10.1145/1177080.1177101
[4]  
Barford P, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P71, DOI 10.1145/637201.637210
[5]  
Barford P, 2001, IMW 2001: PROCEEDINGS OF THE FIRST ACM SIGCOMM INTERNET MEASUREMENT WORKSHOP, P69
[6]   On IP traceback [J].
Belenky, A ;
Ansari, N .
IEEE COMMUNICATIONS MAGAZINE, 2003, 41 (07) :142-153
[7]   On deterministic packet marking [J].
Belenky, Andrey ;
Ansari, Nirwan .
COMPUTER NETWORKS, 2007, 51 (10) :2677-2700
[8]  
Choi BY, 2004, GLOB TELECOMM CONF, P1448
[9]   Effective traffic measurement using ntop [J].
Deri, L ;
Suin, S .
IEEE COMMUNICATIONS MAGAZINE, 2000, 38 (05) :138-143
[10]   Estimating flow distributions from sampled flow statistics [J].
Duffield, N ;
Lund, C ;
Thorup, M .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2005, 13 (05) :933-946