Detection and identification of network anomalies using sketch subspaces

Detection and identification of network anomalies using sketch subspaces
复制标题

DOI:
10.1145/1177080.1177099
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
Xin Li;Fang Bian;M. Crovella;C. Diot;R. Govindan;G. Iannaccone;Anukool Lakhina
Xin Li;Fang Bian;M. Crovella;C. Diot;R. Govindan;G. Iannaccone;Anukool Lakhina
中科院分区:
其他
文献类型:
--
作者:
Xin Li;Fang Bian;M. Crovella;C. Diot;R. Govindan;G. Iannaccone;Anukool Lakhina

文献摘要

被引文献

相似文献

使用降维技术的网络异常检测最近在文献中受到了很多关注。例如,之前的工作将netflow记录聚合到始发-目的地(OD)流中,产生了一个小得多的维度集,然后可以挖掘出异常情况。然而,这种方法只能识别哪个OD流是异常的,而不能识别导致异常的特定IP流。在本文中,我们展示了如何使用IP流的随机聚合(即草图)来更精确地识别异常的潜在原因。我们展示了如何将流量草图与子空间方法相结合,以(1)高精度地检测异常,(2)识别导致异常的IP流。我们的方法的检测率与以前的方法相当,并且比以前的工作检测到更多的异常,使我们向异常检测和识别的强大在线系统迈进了一步。
Network anomaly detection using dimensionality reduction techniques has received much recent attention in the literature. For example, previous work has aggregated netflow records into origin-destination (OD) flows, yielding a much smaller set of dimensions which can then be mined to uncover anomalies. However, this approach can only identify which OD flow is anomalous, not the particular IP flow(s) responsible for the anomaly. In this paper we show how one can use random aggregations of IP flows (i.e., sketches) to enable more precise identification of the underlying causes of anomalies. We show how to combine traffic sketches with a subspace method to (1) detect anomalies with high accuracy and (2) identify the IP flows(s) that are responsible for the anomaly. Our method has detection rates comparable to previous methods and detects many more anomalies than prior work, taking us a step closer towards a robust on-line system for anomaly detection and identification.