Traffic Anomaly Detection Based on the IP Size Distribution

被引:0
|
作者
Soldo, Fabio [1 ]
Metwally, Ahmed [1 ]
机构
[1] Google Inc, Mountain View, CA 94043 USA
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In this paper we present a data-driven framework for detecting machine-generated traffic based on the IP size, i.e., the number of users sharing the same source IP. Our main observation is that diverse machine-generated traffic attacks share a common characteristic: they induce an anomalous deviation from the expected IP size distribution. We develop a principled framework that automatically detects and classifies these deviations using statistical tests and ensemble learning. We evaluate our approach on a massive dataset collected at Google for 90 consecutive days. We argue that our approach combines desirable characteristics: it can accurately detect fraudulent machine-generated traffic; it is based on a fundamental characteristic of these attacks and is thus robust (e. g., to DHCP re-assignment) and hard to evade; it has low complexity and is easy to parallelize, making it suitable for large-scale detection; and finally, it does not entail profiling users, but leverages only aggregate statistics of network traffic.
引用
收藏
页码:2005 / 2013
页数:9
相关论文
共 50 条
  • [41] An Empirical Evaluation of Entropy-based Traffic Anomaly Detection
    Nychis, George
    Sekar, Vyas
    Andersen, David G.
    Kim, Hyong
    Zhang, Hui
    IMC'08: PROCEEDINGS OF THE 2008 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE, 2008, : 151 - 156
  • [42] Application in Anomaly Detection of Network Traffic Based on Fractal Technology
    He, Yuemei
    Wang, Baomin
    Qiao, Dejun
    MECHANICAL ENGINEERING AND INTELLIGENT SYSTEMS, PTS 1 AND 2, 2012, 195-196 : 987 - 991
  • [43] Anomaly Detection of Network Traffic based on the Largest Lyapunov Exponent
    Xiong, Wei
    Hu, Hanping
    Yang, Yue
    Wang, Qian
    2ND IEEE INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER CONTROL (ICACC 2010), VOL. 4, 2010, : 581 - 585
  • [44] Network Traffic Anomaly Detection Based on Maximum Entropy Model
    Qian Yaguan
    Wu Chunming
    Yang Qiang
    Wang Bin
    CHINESE JOURNAL OF ELECTRONICS, 2012, 21 (03): : 579 - 582
  • [45] AIS-based maritime anomaly traffic detection: A review
    Ribeiro, Claudio, V
    Paes, Aline
    de Oliveira, Daniel
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 231
  • [46] Unsupervised network traffic anomaly detection based on score iterations
    Ping G.
    Zeng T.
    Ye X.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2022, 62 (05): : 819 - 824
  • [47] Detection of network traffic anomaly based on instantaneous parameters analysis
    Yao, Xingmiao
    Zhang, Peng
    Gao, Jie
    Hu, Guangmin
    2006 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY, VOLS 1 AND 2, PROCEEDINGS, 2006, : 336 - +
  • [48] Unsupervised Anomaly Detection for Traffic Surveillance Based on Background Modeling
    Wei, JiaYi
    Zhao, JianFei
    Zhao, YanYun
    Zhao, ZhiCheng
    PROCEEDINGS 2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW), 2018, : 129 - 136
  • [49] Network traffic anomaly detection based on deep learning: a review
    Zhang, Wenjing
    Lei, Xuemei
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2024, 27 (03) : 249 - 257
  • [50] A Network Traffic anomaly Detection method based on CNN and XGBoost
    Niu, Dan
    Zhang, Jin
    Wang, Li
    Yan, Kaihong
    Fu, Tao
    Chen, Xisong
    2020 CHINESE AUTOMATION CONGRESS (CAC 2020), 2020, : 5453 - 5457