Image-based anomaly detection technique: Algorithm, implementation and effectiveness

被引:13
作者
Kim, Seong Soo [1 ]
Reddy, A. L. Narasimha
机构
[1] Samsung Elect Co Ltd, Digital Media R& D Ctr, Seoul 100742, South Korea
[2] Texas A&M Univ, Dept Elect & Comp Engn, College Stn, TX 77843 USA
基金
美国国家科学基金会;
关键词
experimentation with real networks/testbeds; image processing; network anomaly detection; network measurements; statistical analysis; stochastic processes;
D O I
10.1109/JSAC.2006.877215
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The frequent and large-scale network attacks have led to an increased need for developing techniques for analyzing network traffic. This paper presents NetViewer, a network measurement approach that can simultaneously detect, identify, and visualize attacks and anomalous traffic in real-time by passively monitoring packet headers. We propose to represent samples of network packet header data as frames or images. With such a formulation, a series of samples can be seen as a sequence of frames or video, revealing certain kinds of attacks to the human eye. This enables techniques from image processing and video compression to be applied to the packet header data to reveal interesting properties of traffic. We show that "scene change analysis" can reveal sudden changes in traffic behavior or anomalies. We also show that "motion prediction" techniques can be employed to understand the patterns of some of the attacks. We show that it may be feasible to represent multiple pieces of data as different colors of an image enabling a uniform treatment of multidimensional packet header data. We compare the effectiveness of NetViewer with classical detection theory-based Neyman-Pearson test.
引用
收藏
页码:1942 / 1954
页数:13
相关论文
共 23 条
  • [1] [Anonymous], 2003, 2003 C APPL TECHNOLO, P99, DOI 10.1145/863955.863968
  • [2] [Anonymous], P SIGCOMM 03
  • [3] Barford P, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P71, DOI 10.1145/637201.637210
  • [4] Barford P, 2001, IMW 2001: PROCEEDINGS OF THE FIRST ACM SIGCOMM INTERNET MEASUREMENT WORKSHOP, P69
  • [5] SPACE/TIME TRADE/OFFS IN HASH CODING WITH ALLOWABLE ERRORS
    BLOOM, BH
    [J]. COMMUNICATIONS OF THE ACM, 1970, 13 (07) : 422 - &
  • [6] ESTAN C, 2003, P 2003 C APPL TECHN, P137, DOI DOI 10.1145/863955.863972
  • [7] GIBSON JD, 1998, M KAUFMANN SERIES, P247
  • [8] GYAOUROVA A, 2003, UCRLTR200271 LLNL
  • [9] Kilpi J, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P49, DOI 10.1145/637201.637207
  • [10] Kim HR, 2004, PROC INT C TOOLS ART, P30