Entropy-based Robust PCA for Communication Network Anomaly Detection

被引:0
|
作者
Liu, Duo [1 ]
Lung, Chung-Horng [1 ]
Seddigh, Nabil [2 ]
Nandy, Biswajit [2 ]
机构
[1] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON K1S 5B6, Canada
[2] Solana Networks, Ottawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Anomaly detection; Principal Component Analysis; Mahalanobis distance; Temporal correlation; Singular value; decomposition (SVD); Squared prediction error (SPE);
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Principal component analysis (PCA) has received increasing attention as a method to distinguish network traffic anomalies from normal data instances based on its orthogonal linear transformation characteristics and dimensionality reduction technique. To address the issue of parameter sensitivity in the classical PCA, we propose modifications to the classical PCA, called robust PCA in this paper, which exhibits greater flexibility in detecting outliers for different traffic distributions. First, the robust PCA utilizes the Mahalanobis distance function which generates more flexible results than that of the Euclidean distance used in the classical PCA. The second modification to the classical PCA is to take into account the temporal effect of network traffic data by considering the neighbors' corresponding values. Temporal correlation is a practically important feature for network traffic, which the classical PCA does not consider. In addition, the proposed robust PCA also adopts entropy calculation to cope with both numerical and categorical data, as both data types exist in real traffic traces. Finally, using the robust PCA, our experimental results demonstrate the effectiveness in identifying network anomalies.
引用
收藏
页码:171 / 175
页数:5
相关论文
共 50 条
  • [31] An Entropy-based Method for Attack Detection in Large Scale Network
    Liu, T.
    Wang, Z.
    Wang, H.
    Lu, K.
    INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2012, 7 (03) : 509 - 517
  • [32] Entropy-Based Profiling of Network Traffic for Detection of Security Attack
    Lee, Tsern-Huei
    He, Jyun-De
    TENCON 2009 - 2009 IEEE REGION 10 CONFERENCE, VOLS 1-4, 2009, : 2505 - 2509
  • [33] Entropy-Based Maximally Stable Extremal Regions for Robust Feature Detection
    Cai, Huiwen
    Wang, Xiaoyan
    Xia, Ming
    Wang, Yangsheng
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2012, 2012
  • [34] Anomaly Detection in Time Series via Robust PCA
    Jin, Yongjun
    Qiu, Chenlu
    Sun, Lei
    Peng, Xuan
    Zhou, Jianning
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION ENGINEERING (ICITE), 2017, : 352 - 355
  • [35] An information entropy-based fuzzy stochastic configuration network for robust data modeling
    Wang, Degang
    Teng, Fei
    Li, Jie
    Song, Wenyan
    Li, Hongxing
    INFORMATION SCIENCES, 2024, 675
  • [36] Entropy-Based Anomaly Detection Using Observation Points Relations in Wireless Sensor Networks
    Arkan, Ahmad Shahab
    Ahmadi, Mahmood
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 119 (02) : 1783 - 1798
  • [37] PCA-Based Robust Anomaly Detection Using Periodic Traffic Behavior
    Kudo, Takanori
    Morita, Tatsuya
    Matsuda, Takahiro
    Takine, Tetsuya
    2013 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (IEEE ICC), 2013, : 1330 - 1334
  • [38] DroidMalHunter: A Novel Entropy-based Anomaly Detection System to Detect Malicious Android Applications
    Ghaffari, Fariba
    Abadi, Mahdi
    2015 5TH INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE), 2015, : 301 - 306
  • [39] PCA-based multivariate statistical network monitoring for anomaly detection
    Camacho, Jose
    Perez-Villegas, Alejandro
    Garcia-Teodoro, Pedro
    Macia-Fernandez, Gabriel
    COMPUTERS & SECURITY, 2016, 59 : 118 - 137
  • [40] A PCA-based Method for IoT Network Traffic Anomaly Detection
    Dang Hai Hoang
    Ha Duong Nguyen
    2018 20TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2018, : 381 - 386