DocumentCode :
124344
Title :
Volume based anomaly detection using LRD analysis of decomposed network traffic
Author :
Zeb, Khan ; AsSadhan, Basil ; Al-Muhtadi, Jalal ; Alshebeili, Saleh ; Bashaiwth, Abdulmuneem
Author_Institution :
Dept. of Electr. Eng., King Saud Univ., Riyadh, Saudi Arabia
fYear :
2014
fDate :
13-15 Aug. 2014
Firstpage :
52
Lastpage :
57
Abstract :
Network traffic intrusions increase day by day in computer systems. This poses major security threats to computer networks. In this paper, we present an effective approach for anomaly detection in network traffic. We investigate the long-range dependence (LRD) behavior of decomposed network traffic subgroups in different directions with respect the enterprise network. If the network traffic exhibits LRD behavior during normal conditions, then deviation from this property can indicate an abnormality in the traffic. We analyze and evaluate recent Internet traffic captured at King Saud University (KSU). The results and analysis of the proposed approach show that the presence of short duration anomalies affect the LRD behavior of certain traffic subgroups, namely the subgroups in the control plane traffic while the aggregated whole traffic still exhibits LRD. These results show how this approach significantly reduces the amount of traffic to analyze, and more importantly it can detect abnormal behavior that is not detected when looking the traffic as a whole.
Keywords :
Internet; computer network security; telecommunication traffic; Internet traffic; LRD analysis; LRD behavior; abnormal behavior detection; computer networks; computer systems; control plane traffic; decomposed network traffic subgroups; enterprise network; long-range dependence behavior; network traffic intrusions; security threats; volume based anomaly detection; Computer crime; Educational institutions; Internet; Monitoring; Optimization methods; Telecommunication traffic; LRD; Optimization method; anomaly detection; control and data planes traffic; self-similarity; traffic analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovative Computing Technology (INTECH), 2014 Fourth International Conference on
Conference_Location :
Luton
Type :
conf
DOI :
10.1109/INTECH.2014.6927746
Filename :
6927746
Link To Document :
بازگشت