• DocumentCode
    3650471
  • Title

    Network traffic anomaly detection using clustering techniques and performance comparison

  • Author

    Duo Liu;Chung-Horng Lung;Ioannis Lambadaris;Nabil Seddigh

  • Author_Institution
    Department of Systems and Computer Eng. Carleton University, Ottawa, Ontario, Canada
  • fYear
    2013
  • Firstpage
    1
  • Lastpage
    4
  • Abstract
    Real-time network traffic anomaly detection is crucial for the confidentiality, integrity, and security of network information. Machine learning approaches are widely used to distinguish traffic flow outliers based on different anomalies with unique statistical characteristics. K-means clustering and Gaussian Mixture Model (GMM) are effective clustering techniques with many variations and easy to implement. Fuzzy clustering is more flexible than hard clustering and is practical for intrusion detection because of the natural treatment of data using fuzzy clustering. Fuzzy c-means clustering (FCM) is an iteratively optimal algorithm normally based on the least square method to partition data sets, which has high computational overhead. This paper proposes modifications to the objective function and the distance function that reduce the computational complexity of FCM while keeping clustering accurate. A combination of FCM clustering GMM, and feature transformation methods are proposed and a comparison of the related testing results and clustering methods is presented.
  • Keywords
    "Principal component analysis","Covariance matrices","Clustering algorithms","Telecommunication traffic","Gaussian mixture model","Partitioning algorithms"
  • Publisher
    ieee
  • Conference_Titel
    Electrical and Computer Engineering (CCECE), 2013 26th Annual IEEE Canadian Conference on
  • ISSN
    0840-7789
  • Print_ISBN
    978-1-4799-0031-2
  • Type

    conf

  • DOI
    10.1109/CCECE.2013.6567739
  • Filename
    6567739