DocumentCode :
2146820
Title :
A flow-based anomaly detection method using sketch and combinations of traffic features
Author :
Chang, Shuying ; Qiu, Xuesong ; Gao, Zhipeng ; Liu, Ke ; Qi, Feng
Author_Institution :
State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
fYear :
2010
fDate :
25-29 Oct. 2010
Firstpage :
302
Lastpage :
305
Abstract :
With the development of high-speed networks, the challenge of effectively analyzing the massive data source for anomaly detection and diagnosis is yet to be resolved. This paper proposes a new flow-based anomaly detection method based on summary data structures and combinations of traffic features. Using IPFIX flow records as input, parallel sketches are established for chosen traffic features respectively. For each sketch, we use Holt-Winters forecasting technique to achieve their forecast sketches and deviation matrixes. When the deviation exceeds a certain threshold, sub-alarms will be generated. According to the characteristics of various attacks and combinations of traffic features, sub-alarms can be merged into final alarms. While sketches of flows are being constructed, destination addresses are recorded in linked lists which are used to locate victims by a series of set operations. This method can not only detect the existence of anomalies in near real time, but can roughly indicate the anomaly types and locate abnormal addresses.
Keywords :
IP networks; computer network security; data structures; matrix algebra; telecommunication computing; telecommunication traffic; Holt-Winters forecasting technique; IPFIX flow record; deviation matrix; flow-based anomaly detection method; high-speed networks; parallel sketch; summary data structure; traffic feature; Data structures; Databases; Feature extraction; Forecasting; IP networks; Radiation detectors; Smoothing methods; Holt-Winters; anomaly detection; combinations of traffic features; parallel sketch;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and Service Management (CNSM), 2010 International Conference on
Conference_Location :
Niagara Falls, ON
Print_ISBN :
978-1-4244-8910-7
Electronic_ISBN :
978-1-4244-8908-4
Type :
conf
DOI :
10.1109/CNSM.2010.5691206
Filename :
5691206
Link To Document :
بازگشت