DocumentCode
1771522
Title
Proposal of a new information-theory based technique and analysis of traffic anomaly detection
Author
Cuadra-Sanchez, Antonio ; Aracil, Javier ; Ramos de Santiago, Javier
Author_Institution
Indra Sist., S.A., Valladolid, Spain
fYear
2014
fDate
18-20 June 2014
Firstpage
1
Lastpage
6
Abstract
The change-point detection theory is used to identify abrupt changes in the network traffic. The literature has focused on longitudinal traffic analysis, namely, detecting sudden peak changes, rather than analyzing the traffic pattern on a 24h typical day. As traffic varies throughout the day, it is essential to consider the concrete traffic period in which the anomaly occurs, which is useful for checking interconnection agreements amongst operators, something not possible with traditional sudden peak changes techniques. As we introduce in this paper, no author to date has devised to detect changing points inside a typical day traffic pattern, which constitutes an innovative information-theory based technique. The aim of this paper is to present this new technique and to analyze how the different algorithms behave in detecting changing points inside a typical day profile. We conclude that a combination of the algorithms provides better results than the use of a single one. In low traffic periods the tests of goodness-of-fit best detect changing conditions, while in normal traffic periods (daytime) entropy-based algorithms best detect traffic increases; besides, the Statistical Control Charts complements both of them when detecting very abrupt changes regardless the traffic load.
Keywords
entropy; telecommunication traffic; change-point detection theory; entropy-based algorithms; information-theory; interconnection agreements; longitudinal traffic analysis; network traffic abrupt changes; statistical control charts; sudden peak changes techniques; traffic anomaly detection analysis; traffic anomaly detection technique; traffic pattern; Accuracy; Algorithm design and analysis; Control charts; Detection algorithms; Mutual information; Pollution measurement; Signal processing algorithms; Traffic analysis; change-point detection; goodness-of-fit; mutual information; security; statistical control charts;
fLanguage
English
Publisher
ieee
Conference_Titel
Smart Communications in Network Technologies (SaCoNeT), 2014 International Conference on
Conference_Location
Vilanova i la Geltru
Type
conf
DOI
10.1109/SaCoNeT.2014.6867763
Filename
6867763
Link To Document