Uncovering network traffic anomalies based on their sparse distributions

被引:0
作者
GuoZhen Cheng
HongChang Chen
DongNian Cheng
Zhen Zhang
JuLong Lan
机构
[1] National Digital Switching System Engineering and Technological Research Center,
来源
Science China Information Sciences | 2014年 / 57卷
关键词
anomaly detection; feature filtering; multi-resolution analysis; sparse distribution;
D O I
暂无
中图分类号
学科分类号
摘要
Characterizing network traffic with higher-dimensional features results in increased complexity of most detectors and classifiers for identifying traffic anomalies. Several key observations from existing studies confirm that network anomalies are typically distributed in a sparse way, with each anomaly essentially characterized by its lower-dimensional features. Based on this important finding, we exploit sparsity in designing a novel detection method for anomalies that ignores redundancies that are dynamically filtered from the feature sets and accurately classifies anomalies. Comparison of our method with three well known techniques shows a 10% improvement in accuracy with an O (n) complexity of the classifier.
引用
收藏
页码:1 / 11
页数:10
相关论文
共 11 条
  • [1] Paxson V(1995)Wide-area traffic: the failure of poisson modeling IEEE/ACM Trans Netw 1 226-244
  • [2] Floyd S(1994)On the self-similar nature of Ethernet traffic IEEE/ACM Trans Netw 2 1-15
  • [3] Leland W E(1998)The empirical mode decomposition and the Hilbert spectrum for nonlinear and non-stationary time series analysis Proc Roy Soc London Ser A A454 903-995
  • [4] Taqqu M S(2009)Anomaly detection algorithm based on fractal characteristics of large-scale network traffic J Commun China 30 43-53
  • [5] Willinger W(undefined)undefined undefined undefined undefined-undefined
  • [6] Huang N E(undefined)undefined undefined undefined undefined-undefined
  • [7] Shen Z(undefined)undefined undefined undefined undefined-undefined
  • [8] Long S R(undefined)undefined undefined undefined undefined-undefined
  • [9] Xu X D(undefined)undefined undefined undefined undefined-undefined
  • [10] Zhu S R(undefined)undefined undefined undefined undefined-undefined