• DocumentCode
    3440810
  • Title

    Detecting Network Anomalies Using Different Wavelet Basis Functions

  • Author

    Lu, Wei ; Tavallaee, Mahbod ; Ghorbani, Ali A.

  • Author_Institution
    Inf. Security Center of Excellence Fac. of Comput. Sci., New Brunswick Univ., Fredericton, NB
  • fYear
    2008
  • fDate
    5-8 May 2008
  • Firstpage
    149
  • Lastpage
    156
  • Abstract
    Signal processing techniques have been applied recently for analyzing and detecting network anomalies due to their potential to find novel or unknown intrusions. In this paper, we present a novel network anomaly detection approach based on wavelet analysis, approximate autoregressive and outlier detection techniques. In order to characterize network traffic behaviors, we proposed fifteen features and applied them as the input signals in our wavelet-based approach. We then evaluate our approach with the 1999 DARPA intrusion detection dataset and conduct a comprehensive comparison for four different typical wavelet basis functions on detecting network intrusions. Our work aims to unveil a question when applying wavelet techniques for detecting network attacks, that is "do wavelet basis functions have an important impact on the intrusion detection performance?". Moreover, to the best of our knowledge, the work is the first to analyze the 1999 DARPA\´s network traffic using flow data instead of its original raw packet data.
  • Keywords
    autoregressive processes; computer networks; security of data; signal processing; telecommunication traffic; wavelet transforms; 1999 DARPA intrusion detection dataset; approximate autoregressive technique; network anomaly detection; network intrusions; network traffic behaviors; outlier detection technique; signal processing techniques; wavelet analysis; wavelet basis functions; Communication networks; Data security; Face detection; Intrusion detection; Machine learning; Machine learning algorithms; Signal processing algorithms; Telecommunication traffic; Traffic control; Wavelet analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Networks and Services Research Conference, 2008. CNSR 2008. 6th Annual
  • Conference_Location
    Halifax, NS
  • Print_ISBN
    978-0-7695-3135-9
  • Type

    conf

  • DOI
    10.1109/CNSR.2008.75
  • Filename
    4519851