MSCA: An Unsupervised Anomaly Detection System for Network Security in Backbone Network

被引:4
|
作者
Liu, Yating [1 ]
Gu, Yuantao [2 ]
Shen, Xinyue [1 ]
Liao, Qingmin [1 ]
Yu, Quan [3 ]
机构
[1] Tsinghua Univ, Tsinghua Shenzhen Int Grad Sch, Shenzhen 518055, Peoples R China
[2] Tsinghua Univ, Dept Elect & Engn, Beijing 100084, Peoples R China
[3] Peng Cheng Lab, Shenzhen 518055, Peoples R China
基金
中国国家自然科学基金;
关键词
Anomaly detection; Feature extraction; IP networks; Principal component analysis; Standards; Hash functions; Clustering algorithms; association rule mining; backbone network; clustering; random projections; sketches; traffic anomalies; INTRUSION DETECTION; RANDOM-FORESTS; ENTROPY; PCA;
D O I
10.1109/TNSE.2022.3206353
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Anomaly detection is a crucial topic in network security which refers to automatically mining known and unknown attacks or threats. Many detectors have been proposed in the last decade. Nonetheless, a practical solution, which is able to provide a high True Positive Rate (TPR) with an acceptable False Positive Rate (FPR) without any prior information, is still challenging due to the complexity and variability of anomaly pattern. In this article, we propose a novel unsupervised detection system called MSCA which applies multiple sketches, K-means++ unsupervised clustering, and association rule mining to detect traffic anomalies and analyze anomalous features and correlations. It can blindly identify known and unknown traffic anomalies without any labeled traffic or prior signatures about data distribution. Rich traffic data is first aggregated and compacted to traffic flows by sketches, and further detected by the combination of clustering algorithm and voting strategy. Then association rule mining is finally utilized to find the anomalous frequent item-sets and association rules. Numerical experiments on MAWILAB datasets demonstrate that the proposed detection method outperforms other reference unsupervised detection methods. It achieves an accuracy of 99.86%, 99.97%, 97.08%, and 95.19% in overall four detection types including IP and port of source and destination.
引用
收藏
页码:223 / 238
页数:16
相关论文
共 50 条
  • [31] Anomaly detection in network security based on nonparametric techniques
    Kim, Eunhye
    Kim, Sehun
    25TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-7, PROCEEDINGS IEEE INFOCOM 2006, 2006, : 3240 - 3241
  • [32] Method for anomaly detection in network security event stream
    Li, Run-Heng
    Jia, Yan
    Tongxin Xuebao/Journal on Communications, 2009, 30 (12): : 27 - 35
  • [33] Hierarchical Kohonenen net for anomaly detection in network security
    Sarasamma, ST
    Zhu, QMA
    Huff, J
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART B-CYBERNETICS, 2005, 35 (02): : 302 - 312
  • [34] Anomaly detection based on unsupervised niche clustering with application to network intrusion detection
    Leon, E
    Nasraoui, F
    Gomez, J
    CEC2004: PROCEEDINGS OF THE 2004 CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1 AND 2, 2004, : 502 - 508
  • [35] Credit Card Fraud Detection Based on Unsupervised Attentional Anomaly Detection Network
    Jiang, Shanshan
    Dong, Ruiting
    Wang, Jie
    Xia, Min
    SYSTEMS, 2023, 11 (06):
  • [36] An unsupervised ensemble framework for node anomaly behavior detection in social network
    Qing Cheng
    Yun Zhou
    Yanghe Feng
    Zhong Liu
    Soft Computing, 2020, 24 : 6421 - 6431
  • [37] Unsupervised anomaly detection via DBSCaN for KPIs jitters in network managements
    College of Computer Science, National University of Defense Technology, Changsha, China
    不详
    不详
    不详
    Comput. Mater. Continua, 2020, 2 (917-927):
  • [38] An Unsupervised Deep Learning Model for Early Network Traffic Anomaly Detection
    Hwang, Ren-Hung
    Peng, Min-Chun
    Huang, Chien-Wei
    Lin, Po-Ching
    Van-Linh Nguyen
    IEEE ACCESS, 2020, 8 : 30387 - 30399
  • [39] Clusters in chaos: A deep unsupervised learning paradigm for network anomaly detection
    Perumal, Seethalakshmi
    Sujatha, P. Kola
    Krishnaa, S.
    Krishnan, Muralitharan
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2025, 235
  • [40] Unsupervised machine learning for network-centric anomaly detection in IoT
    Bhatia, Randeep
    Benno, Steven
    Esteban, Jairo
    Lakshman, T., V
    Grogan, John
    BIG-DAMA'19: PROCEEDINGS OF THE 3RD ACM CONEXT WORKSHOP ON BIG DATA, MACHINE LEARNING AND ARTIFICIAL INTELLIGENCE FOR DATA COMMUNICATION NETWORKS, 2019, : 42 - 48