Unsupervised Ensemble Anomaly Detection through Time-Periodical Packet Sampling

Unsupervised Ensemble Anomaly Detection through Time-Periodical Packet Sampling
复制标题

DOI:
10.1109/infcomw.2010.5466662
复制
发表时间:
2010-03
期刊:
2010 INFOCOM IEEE Conference on Computer Communications Workshops
影响因子:
--
通讯作者:
Shuichi Nawata;M. Uchida;Yu Gu;M. Tsuru;Y. Oie
Shuichi Nawata;M. Uchida;Yu Gu;M. Tsuru;Y. Oie
中科院分区:
其他
文献类型:
--
作者:
Shuichi Nawata;M. Uchida;Yu Gu;M. Tsuru;Y. Oie

文献摘要

被引文献

相似文献

我们提出了一种异常检测方法,该方法训练描述网络流量正常行为的基线模型,而不使用手动标记的流量数据。训练后的基线分布被用作与审计网络流量进行比较的基础。所提出的方法可以通过使用时间周期性的分组采样来以无监督的方式执行,以达到其预期的不同目的。也就是说,我们利用分组采样的有损性质来从未标记的原始流量数据中提取正常分组。通过使用真实的流量轨迹,我们证明了该方法与传统的需要人工标记流量数据来训练基线模型的方法相比,在检测关于TCPSYN分组的异常方面具有相当的误检率和漏检率。此外,为了缓解采样流量数据的概率特性可能带来的性能差异,我们设计了一种并行利用多个基线模型的集成异常检测方法。实验结果表明,该集成异常检测算法具有较好的检测性能,且不受数据包采样时序变化的影响。
We propose an anomaly detection method that trains a baseline model describing the normal behavior of network traffic without using manually labeled traffic data. The trained baseline distribution is used as the basis for comparison with the audit network traffic. The proposed method can be carried out in an unsupervised manner through the use of time-periodical packet sampling for a different purpose from which it was intended. That is, we take advantage of the lossy nature of packet sampling for the purpose of extracting normal packets from the unlabeled original traffic data. By using real traffic traces, we show that the proposed method is comparable in terms of false positive and false negative rates on detecting anomalies regarding TCP SYN packets to the conventional method that requires manually labeled traffic data to train the baseline model. In addition, in order to mitigate the possible performance variation due to probabilistic nature of sampled traffic data, we devised an ensemble anomaly detection method that exploits multiple baseline models in parallel. Experimental results show that the proposed ensemble anomaly detection performs well and is not affected by the variability of time-periodical packet sampling.