Detection of Network Attacks Using Hybrid ARIMA-GARCH Model

被引:4
作者
Andrysiak, Tomasz [1 ]
Saganowski, Lukasz [1 ]
Maszewski, Miroslaw [1 ]
Marchewka, Adam [1 ]
机构
[1] Univ Technol & Life Sci UTP, Inst Telecommun, Fac Telecommun & Elect Engn, Ul Kaliskiego 7, PL-85789 Bydgoszcz, Poland
来源
ADVANCES IN DEPENDABILITY ENGINEERING OF COMPLEX SYSTEMS | 2018年 / 582卷
关键词
Time series analysis; Network traffic prediction; Network attacks detection; Hybrid ARIMA-GARCH model; ANOMALY DETECTION;
D O I
10.1007/978-3-319-59415-6_1
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this article, an attempt to solve the problem of attacks (anomalies) detection in the analyzed network traffic with the use of a mixed statistical model (hybrid) ARIMA-GARCH is presented. The introductory actions consisted in normalization of elements of the analyzed time series by means of the Box-Cox transformation. To determine, though, if the analyzed time series were characterized by heteroscedasticity, they were subjected to the White's test. For comparison, there were also tested with the use of differing statistical approaches (described by mean or conditional variance), realized by individual models of ARIMA and GARCH. The choice of optimal models' parameters was performed as a compromise between the coherence of the model and the size of estimation error. To detect attacks (anomalies) in the network traffic, there were used relations between the proper estimated model of the network traffic, and its real parameters. The presented experimental results confirmed fitness and efficiency of the proposed solutions.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 24 条
  • [1] Andersen T.G., 1998, ENCY STAT SCI, VII
  • [2] Network Traffic Prediction and Anomaly Detection Based on ARFIMA Model
    Andrysiak, Tomasz
    Saganowski, Lukasz
    Choras, Michal
    Kozik, Rafal
    [J]. INTERNATIONAL JOINT CONFERENCE SOCO'14-CISIS'14-ICEUTE'14, 2014, 299 : 545 - 554
  • [3] [Anonymous], 2006, Introduction to Time Series and Forecasting
  • [4] Axelsson S., 2000, 9915 DEP COMP ENG
  • [5] Fractionally integrated generalized autoregressive conditional heteroskedasticity
    Baillie, RT
    Bollerslev, T
    Mikkelsen, HO
    [J]. JOURNAL OF ECONOMETRICS, 1996, 74 (01) : 3 - 30
  • [6] Barford P, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P71, DOI 10.1145/637201.637210
  • [7] GENERALIZED AUTOREGRESSIVE CONDITIONAL HETEROSKEDASTICITY
    BOLLERSLEV, T
    [J]. JOURNAL OF ECONOMETRICS, 1986, 31 (03) : 307 - 327
  • [8] Box G. E. P., 1970, Time series analysis, forecasting and control
  • [9] AN ANALYSIS OF TRANSFORMATIONS
    BOX, GEP
    COX, DR
    [J]. JOURNAL OF THE ROYAL STATISTICAL SOCIETY SERIES B-STATISTICAL METHODOLOGY, 1964, 26 (02) : 211 - 252
  • [10] AUTOREGRESSIVE CONDITIONAL HETEROSCEDASTICITY WITH ESTIMATES OF THE VARIANCE OF UNITED-KINGDOM INFLATION
    ENGLE, RF
    [J]. ECONOMETRICA, 1982, 50 (04) : 987 - 1007