• DocumentCode
    2079177
  • Title

    Traffic Anomaly Detection at Fine Time Scales with Bayes Nets

  • Author

    Kline, Jeff ; Nam, Sangnam ; Barford, Paul ; Plonka, David ; Ron, Amos

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Wisconsin-Madison, Madison, WI
  • fYear
    2008
  • fDate
    June 29 2008-July 5 2008
  • Firstpage
    37
  • Lastpage
    46
  • Abstract
    Traffic anomaly detection using high performance measurement systems offers the possibility of improving the speed of detection and enabling detection of important, short-lived anomalies. In this paper we investigate the problem of detecting anomalies using traffic measurements with fine-grained timestamps. We develop a new detection algorithm (called S3) that utilizes a Bayes Net to efficiently consider multiple input signals and to explicitly define what is considered "anomalous\´\´. The input signals considered by S3 are traffic volumes and correlations between ingress/egress packet and bit rates. These complementary signals enable identification of an expanded range of anomalies. Using a set of high precision traffic measurements collected at our campus border router over a 10 month period and an annotated anomaly log supplied by our network operators, we show that S3 is highly accurate, identifying 86% of the anomalies listed in the log. Compared with well known time series-based and wavelet-based detectors, this represents over a 20% improvement inaccuracy. Investigation of events identified by S3 that did not appear in the operator log indicate many are, in fact, true positives. Deployment of S3 in an operational environment supports this by showing zero false positives during initial tests.
  • Keywords
    Bayes methods; telecommunication security; telecommunication traffic; wavelet transforms; wide area networks; Bayes nets; fine time scales; fine-grained timestamps; high performance measurement systems; traffic anomaly detection; wavelet-based detectors; Bit rate; Detection algorithms; Detectors; Event detection; Internet; Measurement; Monitoring; Protection; Signal processing; Telecommunication traffic; anomaly detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Monitoring and Protection, 2008. ICIMP '08. The Third International Conference on
  • Conference_Location
    Bucharest
  • Print_ISBN
    978-0-7695-3189-2
  • Electronic_ISBN
    978-0-7695-3189-2
  • Type

    conf

  • DOI
    10.1109/ICIMP.2008.33
  • Filename
    4561324