Unsupervised Network Anomaly Detection in Real-Time on Big Data

Unsupervised Network Anomaly Detection in Real-Time on Big Data
复制标题

大数据实时无监督网络异常检测

DOI:
10.1007/978-3-319-23201-0_22
复制
发表时间:
2015
期刊:
Microelectron. J.
影响因子:
--
通讯作者:
P. Owezarski
P. Owezarski
中科院分区:
--
文献类型:
--
作者:
J. Dromard;Gilles Roudière;P. Owezarski

文献摘要

被引文献

相似文献

网络异常检测依赖于基于知识库的入侵检测系统。然而,建立这种知识可能需要时间,因为它需要专家的人工检查。现有的入侵检测系统无法应对零日攻击和新用户的入侵行为,从而无法正确检测入侵。无监督网络异常检测器克服了这个问题,因为不需要先前的知识。相反,这些系统可能非常慢,因为它们需要学习流量的模式,以便获得检测异常流量的必要知识。为了提高速度,这些系统通常只暴露于采样流量,有害流量可以避免检测器检查。在本文中,我们提出利用新的分布式计算框架,以加快无监督网络异常检测算法,UNADA。评价表明,执行时间可以缩短13倍,使联合国反兴奋剂机构能够真实的处理大量的交通痕迹。
Network anomaly detection relies on intrusion detection systems based on knowledge databases. However, building this knowledge may take time as it requires manual inspection of experts. Actual detection systems are unable to deal with 0-day attack or new user’s behavior and in consequence they may fail in correctly detecting intrusions. Unsupervised network anomaly detectors overcome this issue as no previous knowledge is required. In counterpart, these systems may be very slow as they need to learn traffic’s pattern in order to acquire the necessary knowledge to detect anomalous flows. To improve speed, these systems are often only exposed to sampled traffic, harmful traffic may then avoid the detector examination. In this paper, we propose to take advantage of new distributed computing framework in order to speed up an Unsupervised Network Anomaly Detector Algorithm, UNADA. The evaluation shows that the execution time can be improved by a factor of 13 allowing UNADA to process large traces of traffic in real time.