A Hybrid Model for BGP Anomaly Detection Using Median Absolute Deviation and Machine Learning

被引:0
|
作者
Romo-Chavero, Maria Andrea [1 ]
Alatorre, Gustavo De Los Rios
Cantoral-Ceballos, Jose Antonio [1 ]
Perez-Diaz, Jesus Arturo [1 ]
Martinez-Cagnazzo, Carlos
机构
[1] Tecnol Monterrey, Sch Engn & Sci, Monterrey 64849, Mexico
关键词
Anomaly detection; border gateway protocol; machine learning; median absolute deviation; statistics;
D O I
10.1109/OJCOMS.2025.3550010
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Detecting anomalies in the Border Gateway Protocol (BGP) has proved relevant in the cybersecurity field due to the protocol's critical role in the Internet's infrastructure. BGP vulnerabilities can lead to major disruptions and connectivity failures, highlighting the need for early detection to maintain stable and secure Internet services. To address this challenge, our article presents an enhanced version of our previously published Median Absolute Deviation (MAD) anomaly detection system. We introduce a novel dynamic threshold mechanism that significantly enhances anomaly detection performance in BGP, achieving superior accuracy and F1-score. Through a comparative analysis of machine learning (ML) classification models-including Random Forest, Extra Trees, XGBoost, LightGBM, and CatBoost-we demonstrate that integrating our MAD detection system with these ML models can improve anomaly detection significantly. Additionally, we explore how MAD performs when combined with neural networks such as RNN, GRU, and LSTM, providing a valuable comparison between machine learning and neural network-based approaches. We evaluate the models performance in well-known events, such as CodeRed 1 v2, Slammer, Nimda, the Moscow blackout, and the Telekom Malaysia (TMnet) misconfiguration. Our results show an overall accuracy of 0.99 and F1-score of 0.98, demonstrating the effective integration of MAD and ML models for the identification of security threats. Our approach enables proactive detection with minimal computational costs and reduced preprocessing, proving that efficient anomaly detection is achievable.
引用
收藏
页码:2102 / 2116
页数:15
相关论文
共 50 条
  • [21] Abnormal Training Samples Detection Method Based on Median Absolute Deviation
    Gong Xunqiang
    Zhang Fangze
    Lu Tieding
    Chen Zhigao
    LASER & OPTOELECTRONICS PROGRESS, 2020, 57 (23)
  • [22] Effective anomaly detection in hybrid wireless IoT environment through machine learning model: a survey
    Shanmuganathan V.
    Annamalai S.
    International Journal of Mobile Network Design and Innovation, 2023, 10 (04) : 175 - 181
  • [23] Efficient BGP Intrusion Detection Model Using Machine Learning: A Comparative Study with AdaBoost as the Optimal Classifier
    Abdoun, Manaf
    Guennoun, Mouhcine
    Amar, Amine
    Saad, Tarek
    Taha, Mostafa
    2023 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, CCECE, 2023,
  • [24] Anomaly Detection using Machine Learning with a Case Study
    Jidiga, Goverdhan Reddy
    Sammulal, P.
    2014 INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION CONTROL AND COMPUTING TECHNOLOGIES (ICACCCT), 2014, : 1060 - 1065
  • [25] Anomaly detection in IoT environment using machine learning
    Bilakanti, Harini
    Pasam, Sreevani
    Palakollu, Varshini
    Utukuru, Sairam
    SECURITY AND PRIVACY, 2024, 7 (03)
  • [26] Anomaly Detection in Smart Grids using Machine Learning
    Shabad, Prem Kumar Reddy
    Alrashide, Abdulmueen
    Mohammed, Osama
    IECON 2021 - 47TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2021,
  • [27] Internet of Things Anomaly Detection using Machine Learning
    Njilla, Laruent
    Pearlstein, Larry
    Wu, Xin-Wen
    Lutz, Adam
    Ezekiel, Soundararajan
    2019 IEEE APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP (AIPR), 2019,
  • [28] IP Network Anomaly Detection using Machine Learning
    Nair, Roshan
    Kasula, Chaithanya Pramodh
    Vankayala, Sravanthi
    Chakraborty, Niloy
    2019 IEEE 5TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2019,
  • [29] Geochemical anomaly detection in the Irankuh District using Hybrid Machine learning technique and fractal modeling
    Afzal, Peyman
    Farhadi, Sasan
    Konari, Mina Boveiri
    Meigoony, Mojtaba Shamseddin
    Saein, Lili Daneshvar
    GEOPERSIA, 2022, 12 (01): : 191 - 199
  • [30] INTELLIGENT ANOMALY DETECTION MODEL FOR ATM BOOTH SURVEILLANCE USING MACHINE LEARNING ALGORITHM
    Viji, S.
    Kannan, R.
    Jayalashmi, N. Yogambal
    2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, AND INTELLIGENT SYSTEMS (ICCCIS), 2021, : 1007 - 1012