DocumentCode :
524585
Title :
A wavelet-based anomaly detection for outbound network traffic
Author :
Limthong, Kriangkrai ; Watanapongse, Pirawat ; Kensuke, F.
Author_Institution :
Grad. Univ. for Adv. Studies (Sokendai), Tokyo, Japan
fYear :
2010
fDate :
15-18 June 2010
Firstpage :
1
Lastpage :
6
Abstract :
Monitoring and detecting network anomalies are indispensable activities for network administrators. Most anomaly detection techniques focus on inbound traffic (traffic from the Internet entering a customer network) rather than outbound traffic. However, anomalous inbound traffic patterns will be significantly different from anomalous outbound traffic. For network operators, outbound traffic is as important as inbound traffic because they can monitor unwanted activities in their networks to prevent it from affecting other networks. In this paper, we propose a statistic-based anomaly detection method for outbound traffic. Our method involves wavelet-based analysis and a statistical distance calculation of 3 month-long traces on outbound traffic from the computer center in Kasetsart University, which had about 1,300 users per day. We added six types of synthetic incidents to four original protocol-based time series (TCP SYN, TCP SYN/ACK, ICMP, and UDP) and investigated ability of our method to detect these anomalies. Our technique could discover short duration malicious behavior in a moderate volume of packets as well as long duration anomalous behavior in a small volume of packets. The experimental results include the detection accuracy and the false positive rates of several wavelet components, and they indicate that our technique is useful for detecting malicious and anomalous behavior in outbound traffic at a network edge.
Keywords :
security of data; telecommunication security; telecommunication traffic; wavelet transforms; inbound traffic; outbound network traffic; outbound traffic; wavelet-based anomaly detection; Computer crime; Computer networks; Computerized monitoring; Electronic mail; IP networks; Informatics; Signal processing; Telecommunication traffic; Viruses (medical); Wavelet analysis; anomaly detection; network traffic; outbound; statistical distance; time series; wavelet;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information and Telecommunication Technologies (APSITT), 2010 8th Asia-Pacific Symposium on
Conference_Location :
Kuching
Print_ISBN :
978-1-4244-6413-5
Electronic_ISBN :
978-4-88552-244-4
Type :
conf
Filename :
5532070
Link To Document :
بازگشت