Entropy-based Robust PCA for Communication Network Anomaly Detection

被引:0
|
作者
Liu, Duo [1 ]
Lung, Chung-Horng [1 ]
Seddigh, Nabil [2 ]
Nandy, Biswajit [2 ]
机构
[1] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON K1S 5B6, Canada
[2] Solana Networks, Ottawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Anomaly detection; Principal Component Analysis; Mahalanobis distance; Temporal correlation; Singular value; decomposition (SVD); Squared prediction error (SPE);
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Principal component analysis (PCA) has received increasing attention as a method to distinguish network traffic anomalies from normal data instances based on its orthogonal linear transformation characteristics and dimensionality reduction technique. To address the issue of parameter sensitivity in the classical PCA, we propose modifications to the classical PCA, called robust PCA in this paper, which exhibits greater flexibility in detecting outliers for different traffic distributions. First, the robust PCA utilizes the Mahalanobis distance function which generates more flexible results than that of the Euclidean distance used in the classical PCA. The second modification to the classical PCA is to take into account the temporal effect of network traffic data by considering the neighbors' corresponding values. Temporal correlation is a practically important feature for network traffic, which the classical PCA does not consider. In addition, the proposed robust PCA also adopts entropy calculation to cope with both numerical and categorical data, as both data types exist in real traffic traces. Finally, using the robust PCA, our experimental results demonstrate the effectiveness in identifying network anomalies.
引用
收藏
页码:171 / 175
页数:5
相关论文
共 50 条
  • [1] Entropy-Based Anomaly Detection in a Network
    Ajay Shankar Shukla
    Rohit Maurya
    Wireless Personal Communications, 2018, 99 : 1487 - 1501
  • [2] Entropy-based Network Anomaly Detection
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    2017 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016, : 334 - 340
  • [3] Entropy-Based Anomaly Detection in a Network
    Shukla, Ajay Shankar
    Maurya, Rohit
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (04) : 1487 - 1501
  • [4] An Entropy-Based Network Anomaly Detection Method
    Berezinski, Przemyslaw
    Jasiul, Bartosz
    Szpyrka, Marcin
    ENTROPY, 2015, 17 (04) : 2367 - 2408
  • [5] Entropy-Based Feature Selection for Network Anomaly Detection
    Alabi, Ruth
    Yurtkan, Kamil
    2018 2ND INTERNATIONAL SYMPOSIUM ON MULTIDISCIPLINARY STUDIES AND INNOVATIVE TECHNOLOGIES (ISMSIT), 2018, : 563 - 569
  • [6] Machine Learning Enhanced Entropy-Based Network Anomaly Detection
    Timcenko, Valentina
    Gajin, Slavko
    ADVANCES IN ELECTRICAL AND COMPUTER ENGINEERING, 2021, 21 (04) : 51 - 60
  • [7] An Efficient Entropy-based Network Anomaly Detection Method Using MIB
    Zhao, Lei
    Wang, Fu
    PROCEEDINGS OF 2014 IEEE INTERNATIONAL CONFERENCE ON PROGRESS IN INFORMATICS AND COMPUTING (PIC), 2014, : 428 - 432
  • [8] CUSUM-based and Entropy-based Network Anomaly Detection: an Experimental Comparison
    Callegari, Christian
    Pagano, Michele
    Giordano, Stefano
    Berizzi, Fabrizio
    PROCEEDINGS OF THE 2017 8TH INTERNATIONAL CONFERENCE ON THE NETWORK OF THE FUTURE (NOF), 2017, : 132 - 134
  • [9] ADMIRE: Anomaly detection method using entropy-based PCA with three-step sketches
    Kanda, Yoshiki
    Fontugne, Romain
    Fukuda, Kensuke
    Sugawara, Toshiharu
    COMPUTER COMMUNICATIONS, 2013, 36 (05) : 575 - 588
  • [10] ENTVis: A Visual Analytic Tool for Entropy-Based Network Traffic Anomaly Detection
    Zhou, Fangfang
    Huang, Wei
    Zhao, Ying
    Shi, Yang
    Liang, Xing
    Fan, Xiaoping
    IEEE COMPUTER GRAPHICS AND APPLICATIONS, 2015, 35 (06) : 42 - 50