DocumentCode :
1796440
Title :
Entropy-based robust PCA for communication network anomaly detection
Author :
Duo Liu ; Chung-Horng Lung ; Seddigh, Nabil ; Nandy, Biswajit
Author_Institution :
Dept. of Syst. & Comput. Eng., Carleton Univ., Ottawa, ON, Canada
fYear :
2014
fDate :
13-15 Oct. 2014
Firstpage :
171
Lastpage :
175
Abstract :
Principal component analysis (PCA) has received increasing attention as a method to distinguish network traffic anomalies from normal data instances based on its orthogonal linear transformation characteristics and dimensionality reduction technique. To address the issue of parameter sensitivity in the classical PCA, we propose modifications to the classical PCA, called robust PCA in this paper, which exhibits greater flexibility in detecting outliers for different traffic distributions. First, the robust PCA utilizes the Mahalanobis distance function which generates more flexible results than that of the Euclidean distance used in the classical PCA. The second modification to the classical PCA is to take into account the temporal effect of network traffic data by considering the neighbors´ corresponding values. Temporal correlation is a practically important feature for network traffic, which the classical PCA does not consider. In addition, the proposed robust PCA also adopts entropy calculation to cope with both numerical and categorical data, as both data types exist in real traffic traces. Finally, using the robust PCA, our experimental results demonstrate the effectiveness in identifying network anomalies.
Keywords :
IP networks; computer network security; principal component analysis; sensitivity analysis; telecommunication traffic; Euclidean distance; IP address; Mahalanobis distance function; communication network traffic anomaly detection; dimensionality reduction technique; entropy-based robust PCA; network traffic data; orthogonal linear transformation characteristics; parameter sensitivity; principal component analysis; temporal correlation; Decision support systems; Privacy; Security; Anomaly detection; Mahalanobis distance; Principal Component Analysis; Singular value decomposition (SVD); Squared prediction error (SPE); Temporal correlation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications in China (ICCC), 2014 IEEE/CIC International Conference on
Conference_Location :
Shanghai
Type :
conf
DOI :
10.1109/ICCChina.2014.7008266
Filename :
7008266
Link To Document :
بازگشت