DocumentCode :
628242
Title :
Network traffic anomaly detection based on growing hierarchical SOM
Author :
Shin-Ying Huang ; Yen-Nun Huang
Author_Institution :
Res. Center for Inf. Technol. Innovation, Acad. Sinica, Taipei, Taiwan
fYear :
2013
fDate :
24-27 June 2013
Firstpage :
1
Lastpage :
2
Abstract :
Network anomaly detection aims to detect patterns in a given network traffic data that do not conform to an established normal behavior. Distinguishing different anomaly patterns from large amount of data can be a challenge, let alone visualizing them in a comparative perspective. Recently, the unsupervised learning method such as the K-means [3], self-organizing map (SOM) [2], and growing hierarchical self-organizing map (GHSOM) [1] have been shown to be able to facilitate network anomaly detection [4][5]. However, there is no study addressing both mining and detecting task. This study leverages the advantage of GHSOM to analyze the network traffic data and visualize the distribution of attack patterns with hierarchical relationship. In the mining stage, the geometric distances between each pattern and its descriptive information are revealed in the topological space. The density and the sample size of each node can help to detect anomalous network traffic. In the detecting stage, this study extends the traditional GHSOM and uses the support vector machine (SVM) [6] to classify network traffic data into the predefined categories. The proposed approach achieves (1) help understand the behaviors of anomalous network traffic data (2) provide effective classification rule to facilitate network anomaly detection and (3) accumulate network anomaly detection knowledge for both mining and detecting purpose. The public dataset and the private dataset are used to evaluate the proposed approach. The expected result is to confirm that the proposed approach can help understand network traffic data, and the detecting mechanism is effective for identifying anomalous behavior.
Keywords :
data analysis; data mining; data visualisation; self-organising feature maps; support vector machines; telecommunication network topology; telecommunication security; telecommunication traffic; unsupervised learning; GHSOM; K-means method; SVM; anomalous network traffic detection; geometric distances; hierarchical SOM; hierarchical self-organizing map; network traffic anomaly detection; network traffic data analysis; pattern detection; public dataset; support vector machine; unsupervised learning method; Data mining; Data visualization; Feature extraction; Forensics; Neural networks; Support vector machines; Telecommunication traffic; Data Classification; Data Clustering; Network anomaly detection; Neural networks; Visualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks (DSN), 2013 43rd Annual IEEE/IFIP International Conference on
Conference_Location :
Budapest
ISSN :
1530-0889
Print_ISBN :
978-1-4673-6471-3
Type :
conf
DOI :
10.1109/DSN.2013.6575338
Filename :
6575338
Link To Document :
بازگشت