• DocumentCode
    2925428
  • Title

    Multi-dimensional traffic anomaly detection based on ICA

  • Author

    Zonglin, Li ; Guangmin, Hu ; Xingmiao, Yao

  • Author_Institution
    Key Lab. of Broadband Opt. Fiber Transm. & Commun. Networks, Univ. of Electron. Sci. & Technol. of China (UESTC), Chengdu, China
  • fYear
    2009
  • fDate
    5-8 July 2009
  • Firstpage
    333
  • Lastpage
    336
  • Abstract
    Some network anomalous events caused by same reason (e.g., DDoS, link failure) tend to present similar unusual change on multiple traffic observations, and this part of traffic usually exhibits anomalous features either on time or frequency domain. Motivated by this fact, this paper introduces a multidimensional traffic anomaly detection method based on independent component analysis (ICA). Considering traffic observation as a mixture of normal and anomaly that respectively generated by different reasons, we generalize ICA technology of blind sources separation problem to separate the potentially anomalous part from characteristics of individual traffic signal on time and frequent domain. We show that how principle component analysis is combined with sliding window analysis, to measure the degree of similarity among multiple abnormal parts with fine granularity. The evaluation using Abilene trace shows that our method is useful to detect anomalous traffic with small volume, and performs better than previous method.
  • Keywords
    blind source separation; independent component analysis; principal component analysis; telecommunication security; telecommunication traffic; Abilene trace; blind sources separation; independent component analysis; multidimensional traffic anomaly detection; principle component analysis; sliding window analysis; traffic observation; Character generation; Communication networks; Event detection; Frequency domain analysis; Independent component analysis; Monitoring; Multidimensional systems; Optical fibers; Signal generators; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications, 2009. ISCC 2009. IEEE Symposium on
  • Conference_Location
    Sousse
  • ISSN
    1530-1346
  • Print_ISBN
    978-1-4244-4672-8
  • Electronic_ISBN
    1530-1346
  • Type

    conf

  • DOI
    10.1109/ISCC.2009.5202265
  • Filename
    5202265