DocumentCode :
1799827
Title :
Network Traffic Anomaly Detection Using Adaptive Density-Based Fuzzy Clustering
Author :
Duo Liu ; Chung-Horng Lung ; Seddigh, Nabil ; Nandy, Biswajit
Author_Institution :
Dept. of Syst. & Comput. Eng., Carleton Univ., Ottawa, ON, Canada
fYear :
2014
fDate :
24-26 Sept. 2014
Firstpage :
823
Lastpage :
830
Abstract :
Fuzzy C-means (FCM) clustering has been used to distinguish communication network traffic outliers based on the uncommon statistical characteristics of network traffic data. The raditional FCM does not leverage spatial information in its analysis, which leads to inaccuracies in certain instances. To address this challenge, this paper proposes an adaptive fuzzy clustering technique based on existing possibilistic clustering algorithms. The proposed technique simultaneously considers distance, density, and the trend of density change of data instances in the membership degree calculation. Specifically the membership degree is quickly updated when the distance or density is beyond the pre-defined threshold, or density change does not match the data distribution. In contrast, the traditional FCM updates its membership degree only based on the distance between data points and the cluster centroid. The proposed approach enables the clustering to reflect the inherent diversity nature of communication network traffic. Further, an adaptive threshold is introduced to speed up the iterative clustering process. The proposed algorithm has been evaluated via experiments using traffic from a real network. The results indicate that the adaptive fuzzy clustering reduces false negatives while improves true positive results.
Keywords :
data handling; fuzzy set theory; pattern clustering; statistical analysis; FCM clustering; adaptive density-based fuzzy clustering; data distribution; fuzzy C-means clustering; network traffic anomaly detection; network traffic data; spatial information; statistical characteristics; Conferences; Privacy; Security; Fuzzy C-means; Network anomaly detection; Partitional clustering; Possibilistic clustering;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2014 IEEE 13th International Conference on
Conference_Location :
Beijing
Type :
conf
DOI :
10.1109/TrustCom.2014.109
Filename :
7011333
Link To Document :
بازگشت