DocumentCode
3120053
Title
Anomaly prediction in network traffic using adaptive Wiener filtering and ARMA modeling
Author
Celenk, Mehmet ; Conley, Thomas ; Graham, James ; Willis, John
Author_Institution
Sch. of Electr. Eng. & Comput. Sci., Ohio Univ., Athens, OH
fYear
2008
fDate
12-15 Oct. 2008
Firstpage
3548
Lastpage
3553
Abstract
Fast and efficient detection of anomalies is essential for maintaining a robust and secure network. This research presents a method of anomaly detection based on adaptive Wiener filtering of noise followed by ARMA modeling of network flow data. We dynamically calculate noise and traffic signal statistics using network-monitoring metrics for traffic features such as average port, high port, server ports, and peered ports. The underlying approach is tested on near-real-time Internet traffic in the wide-area network (WAN) of Ohio University. The average port feature is determined to be the most informative measure in the estimation process. High port, server ports, and peered ports are used for confirmation of the anomaly detection result. We empirically determine that most of the network features obey Gaussian-like distributions. Experiments reveal that the method is highly effective in predicting anomalies in network traffic flow and preventing any hazard that they may cause.
Keywords
Gaussian distribution; Internet; autoregressive moving average processes; estimation theory; noise; security of data; statistical analysis; telecommunication traffic; wide area networks; ARMA modeling; Gaussian-like distributions; adaptive Wiener filtering; anomalies detection; anomaly detection; anomaly prediction; average port; estimation process; high port; near-real-time Internet traffic; network maintenance; network security; network traffic; network-monitoring metrics; noise; peered ports; server ports; traffic signal statistics; wide-area network; Adaptive systems; Network servers; Noise robustness; Predictive models; Statistics; Telecommunication traffic; Testing; Traffic control; Web server; Wiener filter; ARMA modeling; Network anomalies; Wiener filtering; adaptive digital anomaly predictor; majority voting; network security;
fLanguage
English
Publisher
ieee
Conference_Titel
Systems, Man and Cybernetics, 2008. SMC 2008. IEEE International Conference on
Conference_Location
Singapore
ISSN
1062-922X
Print_ISBN
978-1-4244-2383-5
Electronic_ISBN
1062-922X
Type
conf
DOI
10.1109/ICSMC.2008.4811848
Filename
4811848
Link To Document