Similarity as a central approach to flow‐based anomaly detection

Similarity as a central approach to flow‐based anomaly detection
复制标题

DOI:
10.1002/nem.1867
复制
发表时间:
2014-07
影响因子:
1.5
通讯作者:
Martin Drasar;Martin Vizváry;Jan Vykopal
Martin Drasar;Martin Vizváry;Jan Vykopal
中科院分区:
计算机科学4区
文献类型:
--
作者:
Martin Drasar;Martin Vizváry;Jan Vykopal

文献摘要

被引文献

相似文献

网络流量监测目前在大中型网络中是一种常见的做法。基于流的异常检测方法正在受到广泛的研究,因为基于深度包的检测方法已经达到了它们的极限。然而,缺乏全面的研究来描绘这一领域的最新水平。为此,我们对基于流的异常检测方法进行了深入的调查,这些方法在学术会议上发表并被业界使用。我们已经使用任何异常检测方法所固有的相似性的观点来分析这些方法。在此基础上,提出了一种新的网络异常分类方法和一种面向相似度的流检测方法。我们还发现了四个需要进一步研究的问题:缺乏基于流量的评估数据集、不可行的拟议方法基准、过高的假阳性率以及某些异常类别的覆盖范围有限。版权所有©2014 John Wiley&Sons,Ltd.
Network flow monitoring is currently a common practice in mid‐ and large‐size networks. Methods of flow‐based anomaly detection are subject to ongoing extensive research, because detection methods based on deep packets have reached their limits. However, there is a lack of comprehensive studies mapping the state of the art in this area. For this reason, we have conducted a thorough survey of flow‐based anomaly detection methods published on academic conferences and used by the industry. We have analyzed these methods using the perspective of similarity which is inherent to any anomaly detection method. Based on this analysis, we have proposed a new taxonomy of network anomalies and a similarity‐oriented classification of flow‐based detection methods. We have also identified four issues requiring further research: the lack of flow‐based evaluation datasets, infeasible benchmarking of proposed methods, excessive false positive rate and limited coverage of certain anomaly classes. Copyright © 2014 John Wiley & Sons, Ltd.