MSCA: An Unsupervised Anomaly Detection System for Network Security in Backbone Network

被引:4
|
作者
Liu, Yating [1 ]
Gu, Yuantao [2 ]
Shen, Xinyue [1 ]
Liao, Qingmin [1 ]
Yu, Quan [3 ]
机构
[1] Tsinghua Univ, Tsinghua Shenzhen Int Grad Sch, Shenzhen 518055, Peoples R China
[2] Tsinghua Univ, Dept Elect & Engn, Beijing 100084, Peoples R China
[3] Peng Cheng Lab, Shenzhen 518055, Peoples R China
基金
中国国家自然科学基金;
关键词
Anomaly detection; Feature extraction; IP networks; Principal component analysis; Standards; Hash functions; Clustering algorithms; association rule mining; backbone network; clustering; random projections; sketches; traffic anomalies; INTRUSION DETECTION; RANDOM-FORESTS; ENTROPY; PCA;
D O I
10.1109/TNSE.2022.3206353
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Anomaly detection is a crucial topic in network security which refers to automatically mining known and unknown attacks or threats. Many detectors have been proposed in the last decade. Nonetheless, a practical solution, which is able to provide a high True Positive Rate (TPR) with an acceptable False Positive Rate (FPR) without any prior information, is still challenging due to the complexity and variability of anomaly pattern. In this article, we propose a novel unsupervised detection system called MSCA which applies multiple sketches, K-means++ unsupervised clustering, and association rule mining to detect traffic anomalies and analyze anomalous features and correlations. It can blindly identify known and unknown traffic anomalies without any labeled traffic or prior signatures about data distribution. Rich traffic data is first aggregated and compacted to traffic flows by sketches, and further detected by the combination of clustering algorithm and voting strategy. Then association rule mining is finally utilized to find the anomalous frequent item-sets and association rules. Numerical experiments on MAWILAB datasets demonstrate that the proposed detection method outperforms other reference unsupervised detection methods. It achieves an accuracy of 99.86%, 99.97%, 97.08%, and 95.19% in overall four detection types including IP and port of source and destination.
引用
收藏
页码:223 / 238
页数:16
相关论文
共 50 条
  • [1] System and Network Security: Anomaly Detection and Monitoring
    Vadursi, Michele
    Ceccarelli, Andrea
    Duarte, Elias P., Jr.
    Mahanti, Aniket
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2016, 2016 (2016)
  • [2] Unsupervised and Ensemble-based Anomaly Detection Method for Network Security
    Yang, Donghun
    Hwang, Myunggwon
    2022-14TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SMART TECHNOLOGY (KST 2022), 2022, : 75 - 79
  • [3] An Effective Unsupervised Network Anomaly Detection Method
    Bhuyan, Monowar H.
    Bhattacharyya, D. K.
    Kalita, J. K.
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 533 - 539
  • [4] On ubiquitous network security and anomaly detection
    Van Dyke, C
    Koc, CK
    2003 SYMPOSIUM ON APPLICATIONS AND THE INTERNET WORKSHOPS, PROCEEDINGS, 2003, : 374 - 378
  • [5] Unsupervised anomaly detection for network traffic using artificial immune network
    Yuanquan Shi
    Hong Shen
    Neural Computing and Applications, 2022, 34 : 13007 - 13027
  • [6] Unsupervised anomaly detection for network traffic using artificial immune network
    Shi, Yuanquan
    Shen, Hong
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (15): : 13007 - 13027
  • [7] Anomaly Based Network Intrusion Detection with Unsupervised Outlier Detection
    Zhang, Jiong
    Zulkernine, Mohammad
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2388 - 2393
  • [8] Online and Scalable Unsupervised Network Anomaly Detection Method
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (01): : 34 - 47
  • [9] ENAD: An Ensemble Framework for Unsupervised Network Anomaly Detection
    Liao, Jingyi
    Teo, Sin G.
    Kundu, Partha Pratim
    Tram Truong-Huu
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 81 - 88
  • [10] Unsupervised network traffic anomaly detection with deep autoencoders
    Dutta, Vibekananda
    Pawlicki, Marek
    Kozik, Rafal
    Choras, Michal
    LOGIC JOURNAL OF THE IGPL, 2022, 30 (06) : 912 - 925