Title :
Performance evaluation of BGP anomaly classifiers
Author :
Cosovic, Marijana ; Obradovic, Slobodan ; Trajkovic, Ljiljana
Author_Institution :
Univ. of East Sarajevo, East Sarajevo, Bosnia-Herzegovina
Abstract :
Changes in the network topology such as large-scale power outages or Internet worm attacks are events that may induce routing information updates. Border Gateway Protocol (BGP) is by Autonomous Systems (ASes) to address these changes. Network reachability information, contained in BGP update messages, is stored in the Routing Information Base (RIB). Recent BGP anomaly detection systems employ machine learning techniques to mine network data. In this paper, we evaluated performance of several machine learning algorithms for detecting Internet anomalies using RIB. Naive Bayes (NB), Support Vector Machine (SVM), and Decision Tree (J48) classifiers are employed to detect network traffic anomalies. We evaluated feature discretization and feature selection using three data sets of known Internet anomalies.
Keywords :
Bayes methods; Internet; computer network performance evaluation; computer network security; data mining; decision trees; invasive software; learning (artificial intelligence); routing protocols; support vector machines; telecommunication network topology; telecommunication traffic; AS; BGP anomaly classifiers; Internet anomalies; Internet worm attacks; J48; NB; Naive Bayes; RIB; SVM; autonomous systems; border gateway protocol; decision tree classifiers; feature discretization; feature selection; large-scale power outages; machine learning techniques; network data mining; network topology; network traffic anomalies; performance evaluation; routing information base; routing information updates; support vector machine; Accuracy; Classification algorithms; Data models; Internet; Machine learning algorithms; Niobium; Support vector machines; BGP; decision tree; machine learning; naive Bayes; support vector machine;
Conference_Titel :
Digital Information, Networking, and Wireless Communications (DINWC), 2015 Third International Conference on
Conference_Location :
Moscow
Print_ISBN :
978-1-4799-6375-1
DOI :
10.1109/DINWC.2015.7054228