MSCA: An Unsupervised Anomaly Detection System for Network Security in Backbone Network

被引:4
|
作者
Liu, Yating [1 ]
Gu, Yuantao [2 ]
Shen, Xinyue [1 ]
Liao, Qingmin [1 ]
Yu, Quan [3 ]
机构
[1] Tsinghua Univ, Tsinghua Shenzhen Int Grad Sch, Shenzhen 518055, Peoples R China
[2] Tsinghua Univ, Dept Elect & Engn, Beijing 100084, Peoples R China
[3] Peng Cheng Lab, Shenzhen 518055, Peoples R China
基金
中国国家自然科学基金;
关键词
Anomaly detection; Feature extraction; IP networks; Principal component analysis; Standards; Hash functions; Clustering algorithms; association rule mining; backbone network; clustering; random projections; sketches; traffic anomalies; INTRUSION DETECTION; RANDOM-FORESTS; ENTROPY; PCA;
D O I
10.1109/TNSE.2022.3206353
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Anomaly detection is a crucial topic in network security which refers to automatically mining known and unknown attacks or threats. Many detectors have been proposed in the last decade. Nonetheless, a practical solution, which is able to provide a high True Positive Rate (TPR) with an acceptable False Positive Rate (FPR) without any prior information, is still challenging due to the complexity and variability of anomaly pattern. In this article, we propose a novel unsupervised detection system called MSCA which applies multiple sketches, K-means++ unsupervised clustering, and association rule mining to detect traffic anomalies and analyze anomalous features and correlations. It can blindly identify known and unknown traffic anomalies without any labeled traffic or prior signatures about data distribution. Rich traffic data is first aggregated and compacted to traffic flows by sketches, and further detected by the combination of clustering algorithm and voting strategy. Then association rule mining is finally utilized to find the anomalous frequent item-sets and association rules. Numerical experiments on MAWILAB datasets demonstrate that the proposed detection method outperforms other reference unsupervised detection methods. It achieves an accuracy of 99.86%, 99.97%, 97.08%, and 95.19% in overall four detection types including IP and port of source and destination.
引用
收藏
页码:223 / 238
页数:16
相关论文
共 50 条
  • [41] Unsupervised Network Anomaly Detection in Real-Time on Big Data
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    NEW TRENDS IN DATABASES AND INFORMATION SYSTEMS (ADBIS 2015), 2015, 539 : 197 - 206
  • [42] An anomaly aware network embedding framework for unsupervised anomalous link detection
    Dongsheng Duan
    Cheng Zhang
    Lingling Tong
    Jie Lu
    Cunchi Lv
    Wei Hou
    Yangxi Li
    Xiaofang Zhao
    Data Mining and Knowledge Discovery, 2024, 38 : 501 - 534
  • [43] Robust Variational Autoencoders and Normalizing Flows for Unsupervised Network Anomaly Detection
    Najari, Naji
    Berlemont, Samuel
    Lefebvre, Gregoire
    Duffner, Stefan
    Garcia, Christophe
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 281 - 292
  • [44] Unsupervised Anomaly Detection and Localization Based on Deep Spatiotemporal Translation Network
    Ganokratanaa, Thittaporn
    Aramvith, Supavadee
    Sebe, Nicu
    IEEE ACCESS, 2020, 8 : 50312 - 50329
  • [45] Unsupervised Network Anomaly Detection Based on Abnormality Weights and Subspace Clustering
    Zhao, Xuanqiang
    Wang, Guoying
    Li, Zhixing
    2016 SIXTH INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND TECHNOLOGY (ICIST), 2016, : 482 - 486
  • [46] DUdetector: A dual-granularity unsupervised model for network anomaly detection
    Geng, Haijun
    Ma, Qi
    Chi, Haotian
    Zhang, Zhi
    Yang, Jing
    Yin, Xia
    COMPUTER NETWORKS, 2025, 257
  • [47] Unsupervised Anomaly Detection with Distillated Teacher-Student Network Ensemble
    Xiao, Qinfeng
    Wang, Jing
    Lin, Youfang
    Gongsa, Wenbo
    Hu, Ganghui
    Li, Menggang
    Wang, Fang
    ENTROPY, 2021, 23 (02) : 1 - 18
  • [48] Hierarchical Feature Fusion based Reconstruction Network for Unsupervised Anomaly Detection
    Zhao, Binjie
    Nie, Jiahao
    Guan, Siwei
    Wang, Han
    He, Zhiwei
    Gao, Mingyu
    2022 IEEE 27TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2022,
  • [49] Unsupervised Anomaly Detection for Surface Defects With Dual-Siamese Network
    Tao, Xian
    Zhang, Dapeng
    Ma, Wenzhi
    Hou, Zhanxin
    Lu, ZhenFeng
    Adak, Chandranath
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (11) : 7707 - 7717
  • [50] An unsupervised ensemble framework for node anomaly behavior detection in social network
    Cheng, Qing
    Zhou, Yun
    Feng, Yanghe
    Liu, Zhong
    SOFT COMPUTING, 2020, 24 (09) : 6421 - 6431