DocumentCode :
2922834
Title :
Online detection of network traffic anomalies using behavioral distance
Author :
Sengar, Hemant ; Wang, Xinyuan ; Wang, Haining ; Wijesekera, Duminda ; Jajodia, Sushil
Author_Institution :
Technol. Dev. Dept., NuVox Commun., Greenville, SC, USA
fYear :
2009
fDate :
13-15 July 2009
Firstpage :
1
Lastpage :
9
Abstract :
While network-wide anomaly analysis has been well studied, the on-line detection of network traffic anomalies at a vantage point inside the Internet still poses quite a challenge to network administrators. In this paper, we develop a behavioral distance based anomaly detection mechanism with the capability of performing on-line traffic analysis. To construct accurate on-line traffic profiles, we introduce horizontal and vertical distance metrics between various traffic features (i.e., packet header fields) in the traffic data streams. The significant advantages of the proposed approach lie in four aspects: (1) it is efficient and simple enough to process on-line traffic data; (2) it facilitates protocol behavioral analysis without maintaining per-flow state; (3) it is scalable to high speed traffic links because of the aggregation, and (4) using various combinations of packet features and measuring distances between them, it is capable for accurate on-line anomaly detection. We validate the efficacy of our proposed detection system by using network traffic traces collected at Abilene and MAWI high-speed links.
Keywords :
Internet; security of data; telecommunication security; telecommunication traffic; Internet; anomaly detection mechanism; behavioral distance; network administrators; network traffic anomalies; network traffic traces; network-wide anomaly analysis; online anomaly detection; online detection; online traffic analysis; online traffic data; protocol behavioral analysis; traffic data streams; Computer science; Educational institutions; IP networks; Information analysis; Information systems; Performance analysis; Principal component analysis; Protocols; Spine; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Quality of Service, 2009. IWQoS. 17th International Workshop on
Conference_Location :
Charleston, SC
ISSN :
1548-615X
Print_ISBN :
978-1-4244-3875-4
Electronic_ISBN :
1548-615X
Type :
conf
DOI :
10.1109/IWQoS.2009.5201415
Filename :
5201415
Link To Document :
بازگشت