DocumentCode :
2079177
Title :
Traffic Anomaly Detection at Fine Time Scales with Bayes Nets
Author :
Kline, Jeff ; Nam, Sangnam ; Barford, Paul ; Plonka, David ; Ron, Amos
Author_Institution :
Dept. of Comput. Sci., Univ. of Wisconsin-Madison, Madison, WI
fYear :
2008
fDate :
June 29 2008-July 5 2008
Firstpage :
37
Lastpage :
46
Abstract :
Traffic anomaly detection using high performance measurement systems offers the possibility of improving the speed of detection and enabling detection of important, short-lived anomalies. In this paper we investigate the problem of detecting anomalies using traffic measurements with fine-grained timestamps. We develop a new detection algorithm (called S3) that utilizes a Bayes Net to efficiently consider multiple input signals and to explicitly define what is considered "anomalous\´\´. The input signals considered by S3 are traffic volumes and correlations between ingress/egress packet and bit rates. These complementary signals enable identification of an expanded range of anomalies. Using a set of high precision traffic measurements collected at our campus border router over a 10 month period and an annotated anomaly log supplied by our network operators, we show that S3 is highly accurate, identifying 86% of the anomalies listed in the log. Compared with well known time series-based and wavelet-based detectors, this represents over a 20% improvement inaccuracy. Investigation of events identified by S3 that did not appear in the operator log indicate many are, in fact, true positives. Deployment of S3 in an operational environment supports this by showing zero false positives during initial tests.
Keywords :
Bayes methods; telecommunication security; telecommunication traffic; wavelet transforms; wide area networks; Bayes nets; fine time scales; fine-grained timestamps; high performance measurement systems; traffic anomaly detection; wavelet-based detectors; Bit rate; Detection algorithms; Detectors; Event detection; Internet; Measurement; Monitoring; Protection; Signal processing; Telecommunication traffic; anomaly detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Internet Monitoring and Protection, 2008. ICIMP '08. The Third International Conference on
Conference_Location :
Bucharest
Print_ISBN :
978-0-7695-3189-2
Electronic_ISBN :
978-0-7695-3189-2
Type :
conf
DOI :
10.1109/ICIMP.2008.33
Filename :
4561324
Link To Document :
بازگشت