DocumentCode
2104422
Title
Combining statistical and spectral analysis techniques in network traffic anomaly detection
Author
Novakov, Stevan ; Chung-Horng Lung ; Lambadaris, IOannis ; Seddigh, Nabil
Author_Institution
Dept. of Syst. & Comput. Eng., Carleton Univ., Ottawa, ON, Canada
fYear
2012
fDate
2-4 Dec. 2012
Firstpage
94
Lastpage
101
Abstract
Rapid increase in number of computer attacks prompts a need to detect network anomalies quickly and effectively. This area has been widely studied and solutions typically use data not freely available. A labeled available network traffic flow dataset, Kyoto2006+, has been recently created. Most existing works using Kyoto2006+ for network anomaly detection, apply various clustering approaches. Clustering approaches typically require thresholds for minimum size or distance, or the number of clusters. Results could be sensitive to the selection of such thresholds. This paper leverages existing spectral analysis and statistical analysis techniques for network anomaly detection. One well known spectral analysis technique is Haar Wavelet filtering analysis. It measures the amount and magnitude of abrupt changes in data. Another popular approach is a statistical analysis technique called Principal Component Analysis (PCA). PCA describes data in a new dimension to unlock otherwise hidden characteristics. Both approaches have strengths and limitations. In response, this paper proposes a Hybrid PCA-Haar Wavelet Analysis; a modified PCA which incorporates time shifting to account for changes over time is considered. In addition, the hybrid approach uses PCA to describe the data and Haar Wavelet filtering for analysis. Based on prototyping and measurement, an investigation of the Hybrid PCA-Haar Wavelet Analysis technique is performed using the Kyoto2006+ dataset. We present experimental results to demonstrate the accuracy and precision of the hybrid approach as compared to the two algorithms individually. Furthermore, tests to examine the impact of various parameters used in the algorithm are discussed.
Keywords
Haar transforms; computer network security; filtering theory; principal component analysis; spectral analysis; telecommunication traffic; wavelet transforms; Kyoto2006+ dataset; computer attacks; hybrid PCA-Haar wavelet analysis; network traffic anomaly detection; network traffic flow dataset; principal component analysis; Aggregates; Entropy; Size measurement; Wavelet analysis; Haar Wavelet Analysis; Network Anomaly Detection; Principal Component Analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Next Generation Networks and Services (NGNS), 2012
Conference_Location
Faro
Print_ISBN
978-1-4799-2168-3
Type
conf
DOI
10.1109/NGNS.2012.6656106
Filename
6656106
Link To Document