DocumentCode :
3766847
Title :
Time based anomaly detection using residual polynomial fitting on aggregate traffic statistic
Author :
Yudha Purwanto; Kuspriyanto; Hendrawan;Budi Rahardjo
Author_Institution :
Sekolah Tinggi Elektro dan Komunikasi, Institut Teknologi Bandung, Bandung, Indonesia
fYear :
2015
Firstpage :
1
Lastpage :
5
Abstract :
Flashcrowd and Distributed Denial of Service (DDoS) almost has similar symptom across network and server. But security element such Intrusion Detection System (IDS) must handle both differently. If IDS cannot differentiate flashcrowd and DDoS attack, Quality of Service of legal user traffic in flashcrowd will degraded. So it is important for IDS to differentiate between flashcrowd and DDoS. Many earlier comparison method could sense the anomalous event, but not pay much attention to identify which flow was the anomaly. We presented residual calculation between windowed aggregate traffic statistical value combination. With residual calculation among statistical percentile 10th and mean, a high accuracy of flashcrowd and DDoS differentiation of synthetic anomalous event gained. This method could directly identify the anomalous flow and perform visual analysis to detect the start to end of both event.
Keywords :
"Computer crime","Training","Aggregates","Testing","Feature extraction","Fitting","Quality of service"
Publisher :
ieee
Conference_Titel :
Wireless and Telematics (ICWT), 2015 1st International Conference on
Print_ISBN :
978-1-4673-8433-9
Type :
conf
DOI :
10.1109/ICWT.2015.7449256
Filename :
7449256
Link To Document :
بازگشت