Uncovering network traffic anomalies based on their sparse distributions

被引:1
作者
Cheng GuoZhen [1 ]
Chen HongChang [1 ]
Cheng DongNian [1 ]
Zhang Zhen [1 ]
Lan JuLong [1 ]
机构
[1] Natl Digital Switching Syst Engn & Technol Res Ct, Zhengzhou 450002, Peoples R China
基金
中国国家自然科学基金;
关键词
anomaly detection; feature filtering; multi-resolution analysis; sparse distribution;
D O I
10.1007/s11432-014-5087-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Characterizing network traffic with higher-dimensional features results in increased complexity of most detectors and classifiers for identifying traffic anomalies. Several key observations from existing studies confirm that network anomalies are typically distributed in a sparse way, with each anomaly essentially characterized by its lower-dimensional features. Based on this important finding, we exploit sparsity in designing a novel detection method for anomalies that ignores redundancies that are dynamically filtered from the feature sets and accurately classifies anomalies. Comparison of our method with three well known techniques shows a 10% improvement in accuracy with an O (n) complexity of the classifier.
引用
收藏
页码:1 / 11
页数:11
相关论文
共 16 条
[1]  
[Anonymous], P INFOCOM
[2]  
Barford P, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P71, DOI 10.1145/637201.637210
[3]  
Gao J, 2011, IEEE INFOCOM SER, P181, DOI 10.1109/INFCOM.2011.5934982
[4]   The empirical mode decomposition and the Hilbert spectrum for nonlinear and non-stationary time series analysis [J].
Huang, NE ;
Shen, Z ;
Long, SR ;
Wu, MLC ;
Shih, HH ;
Zheng, QN ;
Yen, NC ;
Tung, CC ;
Liu, HH .
PROCEEDINGS OF THE ROYAL SOCIETY A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 1998, 454 (1971) :903-995
[5]  
Klivansky S, 1995, TECHNICAL REPORT
[6]   Mining anomalies using traffic feature distributions [J].
Lakhina, A ;
Crovella, M ;
Diot, C .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2005, 35 (04) :217-228
[7]   Diagnosing network-wide traffic anomalies [J].
Lakhina, A ;
Crovella, M ;
Diot, C .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2004, 34 (04) :219-230
[8]   ON THE SELF-SIMILAR NATURE OF ETHERNET TRAFFIC (EXTENDED VERSION) [J].
LELAND, WE ;
TAQQU, MS ;
WILLINGER, W ;
WILSON, DV .
IEEE-ACM TRANSACTIONS ON NETWORKING, 1994, 2 (01) :1-15
[9]  
Nyalkalkar K, 2011, IEEE INFOCOM SER, P176, DOI 10.1109/INFCOM.2011.5934975
[10]  
Nychis G, 2008, IMC'08: PROCEEDINGS OF THE 2008 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE, P151