• DocumentCode
    3236912
  • Title

    Network anomaly confirmation, diagnosis and remediation

  • Author

    Plonka, David ; Barford, Paul

  • Author_Institution
    Univ. of Wisconsin-Madison, Madison, WI, USA
  • fYear
    2009
  • fDate
    Sept. 30 2009-Oct. 2 2009
  • Firstpage
    128
  • Lastpage
    135
  • Abstract
    Identifying and diagnosing network traffic anomalies, and rectifying their effects are standard, daily activities of network operators. While there is a large and growing literature on techniques for detecting network anomalies, there has been little or no treatment of what to do after a candidate anomaly has been identified. In this paper, we present a first step toward formalizing and automating the time-consuming and challenging tasks associated with network anomaly confirmation, diagnosis and remedy. Our work assumes that potential anomalies are identified either through visual analysis of key traffic measurements or from a Network Anomaly Detection System (NADS). We describe a flexible framework for network anomaly confirmation, diagnosis and remedy that is based on workflow concepts. The key features of this framework include data types/sources, analyses and decision points. We present an instantiation of our framework that includes a taxonomy of network traffic anomalies and detailed steps for confirmation of anomalies associated with malicious attacks. We demonstrate our framework by applying it to traffic in our university network. We propose that our framework is a starting point for streamlining operational tasks associated with traffic anomalies, and for the generation of annotated data sets that can be used in future NADS development.
  • Keywords
    telecommunication security; telecommunication traffic; confirmation; diagnosis; malicious attacks; network anomaly detection system; network traffic; remediation; taxonomy; Electronic mail; History; Information technology; Large-scale systems; Manufacturing processes; Operations research; Queueing analysis; Taxonomy; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication, Control, and Computing, 2009. Allerton 2009. 47th Annual Allerton Conference on
  • Conference_Location
    Monticello, IL
  • Print_ISBN
    978-1-4244-5870-7
  • Type

    conf

  • DOI
    10.1109/ALLERTON.2009.5394858
  • Filename
    5394858