Towards Generalizable Network Anomaly Detection Models

Towards Generalizable Network Anomaly Detection Models
复制标题

迈向可推广的网络异常检测模型

DOI:
10.1109/lcn52139.2021.9525015
复制
发表时间:
2021
期刊:
IEEE Conference on Local Computer Networks (LCN
影响因子:
--
通讯作者:
Arslan, Engin
Arslan, Engin
中科院分区:
--
文献类型:
--
作者:
Arifuzzaman, Md;Islam, Shafkat;Arslan, Engin

文献摘要

被引文献

相似文献

找到网络性能异常的根本原因是满足业务质量要求的关键。在本文中,我们引入机器学习(ML)模型来处理TCP套接字统计数据,以查明数据包丢失和抖动等性能问题的潜在原因。更重要的是,我们引入了一种新的特征工程方法,将训练数据集中的网络相关指标(例如,总数据包计数和往返时间)转换为网络无关的形式,以便能够将模型转移到新的网络设置中,而无需重新训练它们。在各种网络设置中的实验结果表明,所提出的特征工程方法将模型在以前未见过的网络设置中的性能从60%左右提高到近90%。我们相信,跨网络传输机器学习模型的能力将为在生产网络中广泛采用机器学习解决方案铺平道路,在生产网络中收集标记数据是不可能的。
Finding the root causes of network performance anomalies is critical to satisfy the quality of service requirements. In this paper, we introduce machine learning (ML) models to process TCP socket statistics to pinpoint underlying reasons of performance issues such as packet loss and jitter. More importantly, we introduce a novel feature engineering method to transform network-dependent metrics (e.g., total packet count and round trip time) in training datasets into network-independent forms to be able to transfer the models to new network settings without requiring to retrain them. Experimental results in various network settings show that the proposed feature engineering approach improves the performance of the models in previously unseen network settings from around 60% to nearly 90%. We believe ability to transfer ML models across networks will pave the way for wide adoption of ML solutions in production networks where collecting labeled data is not possible.