DocumentCode :
2322586
Title :
Network traffic anomaly detection based on catastrophe theory
Author :
Xiong, Wei ; Xiong, Naixue ; Yang, Laurence T. ; Vasilakos, Athanasios V. ; Wang, Qian ; Hu, Hanping
Author_Institution :
Inst. of Pattern Recognition & AI, Huazhong Univ. of Sci. & Technol., Wuhan, China
fYear :
2010
fDate :
6-10 Dec. 2010
Firstpage :
2070
Lastpage :
2074
Abstract :
Although various methods have been proposed to detect anomalies, they are mostly based on the traditional statistical physics. The traditional statistical physics methods are based on the stationary hypothesis of the network traffic, which always ignore the real catastrophe process when anomalies occur. In order to reflect the catastrophe process of the abnormal network traffic, we present a non-stationary network traffic anomaly detection approach based on catastrophe theory. The cusp catastrophe model is selected to describe the catastrophe feature of the network traffic and the catastrophe distance is defined as an index to assess the deviation from the normal catastrophe model and the serial of catastrophe distance is the main feature to detect anomaly. We evaluate our approach using the 1999 intrusion evaluation data set of network traffic trace provided by The Defense Advanced Research Projects Agency (DARPA). Experiment results show that our approach can effectively detect network anomalies and achieve high detection probability and low false alarms rate.
Keywords :
catastrophe theory; information theory; telecommunication security; telecommunication traffic; DARPA; Defense Advanced Research Projects Agency; catastrophe process; catastrophe theory; cusp catastrophe model; network traffic anomaly detection; stationary hypothesis; statistical physics methods; Anomaly detection; Catastrophe Distance; Cusp Catastrophe Model; Network traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
GLOBECOM Workshops (GC Wkshps), 2010 IEEE
Conference_Location :
Miami, FL
Print_ISBN :
978-1-4244-8863-6
Type :
conf
DOI :
10.1109/GLOCOMW.2010.5700309
Filename :
5700309
Link To Document :
بازگشت