A Hybrid Model for BGP Anomaly Detection Using Median Absolute Deviation and Machine Learning

被引:0
|
作者
Romo-Chavero, Maria Andrea [1 ]
Alatorre, Gustavo De Los Rios
Cantoral-Ceballos, Jose Antonio [1 ]
Perez-Diaz, Jesus Arturo [1 ]
Martinez-Cagnazzo, Carlos
机构
[1] Tecnol Monterrey, Sch Engn & Sci, Monterrey 64849, Mexico
关键词
Anomaly detection; border gateway protocol; machine learning; median absolute deviation; statistics;
D O I
10.1109/OJCOMS.2025.3550010
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Detecting anomalies in the Border Gateway Protocol (BGP) has proved relevant in the cybersecurity field due to the protocol's critical role in the Internet's infrastructure. BGP vulnerabilities can lead to major disruptions and connectivity failures, highlighting the need for early detection to maintain stable and secure Internet services. To address this challenge, our article presents an enhanced version of our previously published Median Absolute Deviation (MAD) anomaly detection system. We introduce a novel dynamic threshold mechanism that significantly enhances anomaly detection performance in BGP, achieving superior accuracy and F1-score. Through a comparative analysis of machine learning (ML) classification models-including Random Forest, Extra Trees, XGBoost, LightGBM, and CatBoost-we demonstrate that integrating our MAD detection system with these ML models can improve anomaly detection significantly. Additionally, we explore how MAD performs when combined with neural networks such as RNN, GRU, and LSTM, providing a valuable comparison between machine learning and neural network-based approaches. We evaluate the models performance in well-known events, such as CodeRed 1 v2, Slammer, Nimda, the Moscow blackout, and the Telekom Malaysia (TMnet) misconfiguration. Our results show an overall accuracy of 0.99 and F1-score of 0.98, demonstrating the effective integration of MAD and ML models for the identification of security threats. Our approach enables proactive detection with minimal computational costs and reduced preprocessing, proving that efficient anomaly detection is achievable.
引用
收藏
页码:2102 / 2116
页数:15
相关论文
共 50 条
  • [1] Median Absolute Deviation for BGP Anomaly Detection
    Romo-Chavero, Maria Andrea
    Cantoral-Ceballos, Jose Antonio
    Perez-Diaz, Jesus Arturo
    Martinez-Cagnazzo, Carlos
    FUTURE INTERNET, 2024, 16 (05)
  • [2] A Survey of BGP Anomaly Detection Using Machine Learning Techniques
    Hammood, Noor Hadi
    Al-Musawi, Bahaa
    Alhilali, Ahmed Hazim
    APPLICATIONS AND TECHNIQUES IN INFORMATION SECURITY (ATIS 2021), 2022, 1554 : 109 - 120
  • [3] Application of machine learning in BGP anomaly detection
    Dai, Xianbo
    Wang, Na
    Wang, Wenjuan
    2018 INTERNATIONAL SEMINAR ON COMPUTER SCIENCE AND ENGINEERING TECHNOLOGY (SCSET 2018), 2019, 1176
  • [4] Comparing Machine Learning Algorithms for BGP Anomaly Detection using Graph Features
    Sanchez, Odnan Ref
    Ferlin, Simone
    Pelsser, Cristel
    Bush, Randy
    BIG-DAMA'19: PROCEEDINGS OF THE 3RD ACM CONEXT WORKSHOP ON BIG DATA, MACHINE LEARNING AND ARTIFICIAL INTELLIGENCE FOR DATA COMMUNICATION NETWORKS, 2019, : 35 - 41
  • [5] IFDRF: Advancing Anomaly Detection with a Hybrid Machine Learning Model
    Ramesh, Hariharan
    Shariaty, Faridoddin
    Roy, Sanjiban Sekhar
    OPTICAL MEMORY AND NEURAL NETWORKS, 2024, 33 (04) : 385 - 400
  • [6] Edge Preserving Image Enhancement using Median Absolute Deviation and Iterative Median Absolute Deviation
    Shivaprasad
    D'Souza, Clitus
    Vinay, P.
    2017 INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER, AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2017, : 208 - 211
  • [7] A hybrid machine learning approach to network anomaly detection
    Shon, Taeshik
    Moon, Jongsub
    INFORMATION SCIENCES, 2007, 177 (18) : 3799 - 3821
  • [8] An Anomaly Detection Model for Oil and Gas Pipelines Using Machine Learning
    Aljameel, Sumayh S.
    Alomari, Dorieh M.
    Alismail, Shatha
    Khawaher, Fatimah
    Alkhudhair, Aljawharah A.
    Aljubran, Fatimah
    Alzannan, Razan M.
    COMPUTATION, 2022, 10 (08)
  • [9] Anomaly detection in Skin Model Shapes using machine learning classifiers
    Yacob, Filmon
    Semere, Daniel
    Nordgren, Erik
    INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2019, 105 (09): : 3677 - 3689
  • [10] Anomaly detection in Skin Model Shapes using machine learning classifiers
    Filmon Yacob
    Daniel Semere
    Erik Nordgren
    The International Journal of Advanced Manufacturing Technology, 2019, 105 : 3677 - 3689