• DocumentCode
    2306841
  • Title

    Network Anomaly Detection Based on Statistical Approach and Time Series Analysis

  • Author

    Kai, Huang ; Zhengwei, Qi ; Bo, Liu

  • Author_Institution
    Sch. of Software Eng., Shanghai Jiao Tong Univ., Shanghai
  • fYear
    2009
  • fDate
    26-29 May 2009
  • Firstpage
    205
  • Lastpage
    211
  • Abstract
    Network always suffers from the traffic anomaly such as router rate change, device restart or the worm attack. The early detection of unusual anomaly in the network is a key to fast recover and avoidance of future serious problem to provide a stable network transmission. In this paper we present a statistical approach to analysis the distribution of network traffic to identify the normal network traffic behavior. We adapt the EM algorithm to estimate the distribution parameter of Gaussian mixture distribution model. If only there is a statistical signature of unusual fluctuation or change in the network traffic an alarm will be triggered. We adapt the time series analysis of the statistical analysis result. Up bound and low bound will be defined through the analysis. The exceeding of the bound will be the signal of traffic anomaly. Another time series analysis approach also can reflect the fluctuation of network with the crossover of two indicator lines called K line and D line. These two indicator lines are some think like the mean value of the historical data in a time slice with one more sensitive to the change of the new coming data and another not. The approach three-MACD indicator approach is like the K D approach but more blunt to the unusual fluctuation of network traffic which can submit an alarm more correctly.
  • Keywords
    Gaussian distribution; security of data; statistical analysis; telecommunication network routing; telecommunication traffic; time series; Gaussian mixture distribution model; network anomaly detection; router rate change; statistical approach; three-MACD indicator approach; time series analysis; traffic anomaly; worm attack; Application software; Communication system traffic control; Fluctuations; Neural networks; Protocols; Software engineering; Statistical analysis; Telecommunication traffic; Time series analysis; Traffic control; EM algorism; Gaussian Mixture Model; K and D indicator approach; MACD (Moving Average Convergence and Divergence);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops, 2009. WAINA '09. International Conference on
  • Conference_Location
    Bradford
  • Print_ISBN
    978-1-4244-3999-7
  • Electronic_ISBN
    978-0-7695-3639-2
  • Type

    conf

  • DOI
    10.1109/WAINA.2009.58
  • Filename
    5136649