Title :
A Taxonomy and Comparative Evaluation of Algorithms for Parallel Anomaly Detection
Author :
Shanbhag, Shashank ; Gu, Yu ; Wolf, Tilman
Author_Institution :
Dept. of Electr. & Comput. Eng., Univ. of Massachusetts, Amherst, MA, USA
Abstract :
Anomaly detection in network traffic is an important technique for identifying operation and security problems in networks. Numerous anomaly detection algorithms have been proposed and deployed in practice. The recent availability of high-performance embedded processors in network systems has made it possible to implement these algorithms to monitor traffic in real-time. Since it is unlikely that any single anomaly detection technique will ever be sufficient, we propose the use of multiple existing anomaly detection algorithms in parallel. In this paper, we develop a method of combining different classes of anomaly detection algorithms and address the question of which combination of existing anomaly detection algorithms achieves the best detection accuracy. We also present a taxonomy of anomaly detection algorithms and evaluate six specific algorithms on a common evaluation platform. Based on this evaluation, we identify the combination of anomaly detection algorithms that achieve the highest detection accuracy and derive a few rules that can be used when deciding on combining and aggregating multiple algorithms.
Keywords :
microprocessor chips; signal detection; telecommunication networks; telecommunication security; telecommunication traffic; detection accuracy; high-performance embedded processors; multiple algorithms; network traffic; parallel anomaly detection; real-time traffic monitoring; security problems; taxonomy; Accuracy; Algorithm design and analysis; Classification algorithms; Clustering algorithms; Detection algorithms; Machine learning algorithms; Measurement;
Conference_Titel :
Computer Communications and Networks (ICCCN), 2010 Proceedings of 19th International Conference on
Conference_Location :
Zurich
Print_ISBN :
978-1-4244-7114-0
DOI :
10.1109/ICCCN.2010.5560167