• DocumentCode
    2335039
  • Title

    URCA: Pulling out Anomalies by their Root Causes

  • Author

    Silveira, F. ; Diot, Christophe

  • fYear
    2010
  • fDate
    14-19 March 2010
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    Traffic anomaly detection has received a lot of attention over recent years, but understanding the nature of these anomalies and identifying the flows involved is still a manual task, in most cases. We introduce Unsupervised Root Cause Analysis (URCA) which isolates anomalous traffic and classifies alarms with minimal manual assistance and high accuracy. URCA proceeds by successive reduction of the anomalous space, eliminating normal traffic based on feedback from the anomaly detection method. Classification is done by clustering a new anomaly with previously labeled events. We validate URCA using manually analyzed real anomalies as well as synthetic anomaly injection. Our validation shows that URCA can accurately diagnose a large range of anomaly types, including network scans, DDoS attacks, and major routing changes.
  • Keywords
    telecommunication congestion control; telecommunication security; anomalous space; anomalous traffic isolation; classification; root causes; traffic anomaly detection; unsupervised root cause analysis; Classification algorithms; Classification tree analysis; Clustering algorithms; Communications Society; Computer crime; Detectors; Feedback; Network-on-a-chip; Routing; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM, 2010 Proceedings IEEE
  • Conference_Location
    San Diego, CA
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4244-5836-3
  • Type

    conf

  • DOI
    10.1109/INFCOM.2010.5462151
  • Filename
    5462151