• DocumentCode
    2146820
  • Title

    A flow-based anomaly detection method using sketch and combinations of traffic features

  • Author

    Chang, Shuying ; Qiu, Xuesong ; Gao, Zhipeng ; Liu, Ke ; Qi, Feng

  • Author_Institution
    State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
  • fYear
    2010
  • fDate
    25-29 Oct. 2010
  • Firstpage
    302
  • Lastpage
    305
  • Abstract
    With the development of high-speed networks, the challenge of effectively analyzing the massive data source for anomaly detection and diagnosis is yet to be resolved. This paper proposes a new flow-based anomaly detection method based on summary data structures and combinations of traffic features. Using IPFIX flow records as input, parallel sketches are established for chosen traffic features respectively. For each sketch, we use Holt-Winters forecasting technique to achieve their forecast sketches and deviation matrixes. When the deviation exceeds a certain threshold, sub-alarms will be generated. According to the characteristics of various attacks and combinations of traffic features, sub-alarms can be merged into final alarms. While sketches of flows are being constructed, destination addresses are recorded in linked lists which are used to locate victims by a series of set operations. This method can not only detect the existence of anomalies in near real time, but can roughly indicate the anomaly types and locate abnormal addresses.
  • Keywords
    IP networks; computer network security; data structures; matrix algebra; telecommunication computing; telecommunication traffic; Holt-Winters forecasting technique; IPFIX flow record; deviation matrix; flow-based anomaly detection method; high-speed networks; parallel sketch; summary data structure; traffic feature; Data structures; Databases; Feature extraction; Forecasting; IP networks; Radiation detectors; Smoothing methods; Holt-Winters; anomaly detection; combinations of traffic features; parallel sketch;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Management (CNSM), 2010 International Conference on
  • Conference_Location
    Niagara Falls, ON
  • Print_ISBN
    978-1-4244-8910-7
  • Electronic_ISBN
    978-1-4244-8908-4
  • Type

    conf

  • DOI
    10.1109/CNSM.2010.5691206
  • Filename
    5691206