Matrix Profile data mining for BGP anomaly detection

被引:6
|
作者
Scott, Ben A. [1 ]
Johnstone, Michael N. [1 ]
Szewczyk, Patryk [1 ]
Richardson, Steven [1 ]
机构
[1] Edith Cowan Univ, Perth, Australia
关键词
Anomaly detection; BGP; Cyber security; Internet security; Network security; Routing; Time series analysis;
D O I
10.1016/j.comnet.2024.110257
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Border Gateway Protocol (BGP), acting as the communication protocol that binds the Internet, remains vulnerable despite Internet security advancements. This is not surprising, as the Internet was not designed to be resilient to cyber-attacks, therefore the detection of anomalous activity was not of prime importance to the Internet creators. Detection of BGP anomalies can potentially provide network operators with an early warning system to focus on protecting networks, systems, and infrastructure from significant impact, improve security posture and resilience, while ultimately contributing to a secure global Internet environment. In this paper, we present a novel technique for the detection of BGP anomalies in different events. This research uses publicly available datasets of BGP messages collected from the repositories, Route Views and Reseaux IP Europeens (RIPE). Our contribution is the application of a time series data mining approach, Matrix Profile (MP), to detect BGP anomalies in all categories of BGP events. Advantages of the MP detection technique compared to extant approaches include that it is domain agnostic, is assumption -free, requires few parameters, does not require training data, and is scalable and storage efficient. The single hyper -parameter analyzed in MP shows it is robust to change. Our results indicate the MP detection scheme is competitive against existing detection schemes. A novel BGP anomaly detection scheme is also proposed for further research and validation.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Sparse Control and Data plane Telemetry features for BGP anomaly detection
    Cordova-Garcia, Jose
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 240 - 245
  • [2] BGP Anomaly Detection Techniques: A Survey
    Al-Musawi, Bahaa
    Branch, Philip
    Armitage, Grenville
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (01): : 377 - 396
  • [3] BGP Anomaly Detection with Balanced Datasets
    Cosovic, Marijana
    Obradovic, Slobodan
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2018, 25 (03): : 766 - 775
  • [4] Data mining methodology for anomaly detection in network data
    Caruso, Costantina
    Malerba, Donato
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS: KES 2007 - WIRN 2007, PT II, PROCEEDINGS, 2007, 4693 : 109 - 116
  • [5] Anomaly Detection in Roads with a Data Mining Approach
    Silva, Nuno
    Soares, Joao
    Shah, Vaibhav
    Santos, Maribel Yasmina
    Rodrigues, Helena
    CENTERIS 2017 - INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS / PROJMAN 2017 - INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT / HCIST 2017 - INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES, CENTERI, 2017, 121 : 415 - 422
  • [6] Median Absolute Deviation for BGP Anomaly Detection
    Romo-Chavero, Maria Andrea
    Cantoral-Ceballos, Jose Antonio
    Perez-Diaz, Jesus Arturo
    Martinez-Cagnazzo, Carlos
    FUTURE INTERNET, 2024, 16 (05)
  • [7] BGP anomaly detection as a group dynamics problem
    Scott, Ben A.
    Johnstone, Michael N.
    Szewczyk, Patryk
    Richardson, Steven
    COMPUTER NETWORKS, 2025, 257
  • [8] Suitability of Graph Representation for BGP Anomaly Detection
    Hoarau, Kevin
    Tournoux, Pierre Ugo
    Razafindralambo, Tahiry
    PROCEEDINGS OF THE IEEE 46TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2021), 2021, : 305 - 310
  • [9] Selection of Effective Features for BGP Anomaly Detection
    Arai, Tatsuya
    Nakano, Kotaro
    Chakraborty, Basabi
    2019 IEEE 10TH INTERNATIONAL CONFERENCE ON AWARENESS SCIENCE AND TECHNOLOGY (ICAST 2019), 2019, : 215 - 220
  • [10] Application of machine learning in BGP anomaly detection
    Dai, Xianbo
    Wang, Na
    Wang, Wenjuan
    2018 INTERNATIONAL SEMINAR ON COMPUTER SCIENCE AND ENGINEERING TECHNOLOGY (SCSET 2018), 2019, 1176