Detection of network anomalies using Improved-MSPCA with sketches

被引:18
作者
Chen, Zhaomin [1 ]
Yeo, Chai Kiat [1 ]
Lee, Bu Sung [1 ]
Lau, Chiew Tong [1 ]
机构
[1] Nanyang Technol Univ, Sch Comp Sci & Engn, Comp Network & Commun Grad Lab, Singapore 639798, Singapore
关键词
Network anomaly; Improved Multi-scale Principal; Component Analysis (Improved-MSPCA); Abnormal subspace; Sketch; Anomalous Source IP addresses; DARPA; MAWI; PCA;
D O I
10.1016/j.cose.2016.10.010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet has become a battle ground between defenders and attackers. The important and first step for a defender of the network is to detect "indicators" of attack. One of the indicators is traffic anomaly. In this paper, we propose an Improved-MSPCA anomaly detection algorithm which can diminish the impact of normal subspace contamination so as to separate the anomalous data more efficiently. Compared to the conventional-MSPCA, our Improved-MSPCA has less parameter setting and lower time complexity. By evaluating on the DAPFtA 1999 datasets, the results indicate that Improved-MSPCA can alleviate the effect of normal subspace contamination and achieve a great improvement compared to the other related detection algorithms. In addition, we propose a novel feature-based anomaly detection system which combines sketch data structure and Improved-MSPCA detection algorithm to detect anomalous IP source addresses. Through experiments on the more recent MAWI datasets, the results demonstrate that our system outperforms other related anomaly detection systems. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:314 / 328
页数:15
相关论文
共 39 条
[1]   Multivariate online anomaly detection using kernel recursive least squares [J].
Ahmed, Tarem ;
Coates, Mark ;
Lakhina, Anukool .
INFOCOM 2007, VOLS 1-5, 2007, :625-+
[2]  
[Anonymous], GLOB TEL C 2006 GLOB
[3]  
[Anonymous], 2010, P 6 INT C EM NETW EX, DOI [10.1145/1921168.1921179, DOI 10.1145/1921168.1921179]
[4]  
[Anonymous], 2010, 2010 IEEE GLOB TEL C
[5]  
Arshad M.H., IDENTIFYING OUTLIERS
[6]   Multiscale PCA with application to multivariate statistical process monitoring [J].
Bakshi, BR .
AICHE JOURNAL, 1998, 44 (07) :1596-1610
[7]  
Barford P, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P71, DOI 10.1145/637201.637210
[8]  
Bishop CM, 1999, ADV NEUR IN, V11, P382
[9]   Seven Years and One Day: Sketching the Evolution of Internet Traffic [J].
Borgnat, Pierre ;
Dewaele, Guillaume ;
Fukuda, Kensuke ;
Abry, Patrice ;
Cho, Kenjiro .
IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-5, 2009, :711-+
[10]   Applying PCA for Traffic Anomaly Detection: Problems and Solutions [J].
Brauckhoff, Daniela ;
Salamatian, Kave ;
May, Martin .
IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-5, 2009, :2866-+