DocumentCode :
775965
Title :
Image-Based Anomaly Detection Technique: Algorithm, Implementation and Effectiveness
Author :
Kim, Seong Soo ; Reddy, A. L Narasimha
Author_Institution :
Digital Media R&D Center, Seoul
Volume :
24
Issue :
10
fYear :
2006
Firstpage :
1942
Lastpage :
1954
Abstract :
The frequent and large-scale network attacks have led to an increased need for developing techniques for analyzing network traffic. This paper presents NetViewer, a network measurement approach that can simultaneously detect, identify, and visualize attacks and anomalous traffic in real-time by passively monitoring packet headers. We propose to represent samples of network packet header data as frames or images. With such a formulation, a series of samples can be seen as a sequence of frames or video, revealing certain kinds of attacks to the human eye. This enables techniques from image processing and video compression to be applied to the packet header data to reveal interesting properties of traffic. We show that "scene change analysis" can reveal sudden changes in traffic behavior or anomalies. We also show that "motion prediction" techniques can be employed to understand the patterns of some of the attacks. We show that it may be feasible to represent multiple pieces of data as different colors of an image enabling a uniform treatment of multidimensional packet header data. We compare the effectiveness of NetViewer with classical detection theory-based Neyman-Pearson test
Keywords :
data compression; data visualisation; eye; image sampling; image sequences; motion estimation; object detection; telecommunication traffic; video coding; NetViewer; anomaly detection; data visualization; frame sequence; human eye; image processing; large-scale network attack; motion prediction technique; multidimensional packet header data; network measurement approach; network traffic analysis; passive monitoring; series of sample; video compression; Data visualization; Humans; Image processing; Large-scale systems; Layout; Monitoring; Multidimensional systems; Telecommunication traffic; Testing; Video compression; Experimentation with real networks/testbeds; image processing; network anomaly detection; network measurements; statistical analysis; stochastic processes;
fLanguage :
English
Journal_Title :
Selected Areas in Communications, IEEE Journal on
Publisher :
ieee
ISSN :
0733-8716
Type :
jour
DOI :
10.1109/JSAC.2006.877215
Filename :
1705624
Link To Document :
بازگشت