Network anomaly detection based on probabilistic analysis

被引:5
|
作者
Park, JinSoo [1 ]
Choi, Dong Hag [1 ]
Jeon, You-Boo [1 ]
Nam, Yunyoung [2 ]
Hong, Min [3 ]
Park, Doo-Soon [3 ]
机构
[1] Soon Chun Hyang Univ, Wellness Coaching Serv Res Ctr, RM U1202,22 Soonchunhyangro, Asan, Choongcheongnam, South Korea
[2] Soon Chun Hyang Univ, Dept Comp Engn, Asan, Choongcheongnam, South Korea
[3] Soon Chun Hyang Univ, Dept Comp Software Engn, Asan, Choongcheongnam, South Korea
关键词
Anomaly detection; Network intrusion; Traffic flood; DDoS attacks; Mahalanobis distance; INTRUSION DETECTION; MODEL; PARALLEL;
D O I
10.1007/s00500-017-2679-3
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this paper, we propose a method to detect network intrusions using anomaly detection technique based on probabilistic analysis. Victim's computers under attack show various symptoms such as degradation of TCP throughput, increase in CPU usage, increased round trip time, frequent disconnection to the Web sites, etc. These symptoms can be used as components to construct the k-dimensional feature space of multivariate normal distribution, in which case an anomaly detection method can be applied for the detection of the attack on the distribution. These features are generally highly correlated. Thus we choose only a few of these features for the anomaly detection in multivariate normal distribution. We use Mahalanobis distance to detect the anomalies for each data, normal, and abnormal. Anomalies are identified when their square root of Mahalanobis distance exceeds certain threshold. A detailed description of the threshold setting and the various experiments are discussed in simulation results.
引用
收藏
页码:6621 / 6627
页数:7
相关论文
共 50 条
  • [21] Anomaly detection of excessive network traffic based on ratio and volume analysis
    Kim, Hyun Joo
    Na, Jung C.
    Jang, Jong S.
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2006, 3975 : 726 - 727
  • [22] Anomaly detection analysis based on correlation of features in graph neural network
    Ko, Hoon
    Praca, Isabel
    Choi, Seong Gon
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (09) : 25487 - 25501
  • [23] Anomaly detection analysis based on correlation of features in graph neural network
    Hoon Ko
    Isabel Praca
    Seong Gon Choi
    Multimedia Tools and Applications, 2024, 83 : 25487 - 25501
  • [24] Network Anomaly Detection Based on Statistical Approach and Time Series Analysis
    Huang Kai
    Qi Zhengwei
    Liu Bo
    2009 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS: WAINA, VOLS 1 AND 2, 2009, : 205 - 211
  • [25] Network Anomaly Detection Method Based on Community Detection
    Qian, Ai-Juan
    Fan, Xin
    Dong, Xiao-Ju
    Chu, Yan-Jie
    Yuan, Xiao-Ru
    Jisuanji Xuebao/Chinese Journal of Computers, 2022, 45 (04): : 825 - 837
  • [26] Network-Wide Traffic Anomaly Detection and Localization Based on Robust Multivariate Probabilistic Calibration Model
    Li, Yuchong
    Luo, Xingguo
    Qian, Yekui
    Zhao, Xin
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2015, 2015
  • [27] RMPCM: network-wide anomaly detection method based on robust multivariate probabilistic calibration model
    National Digital Switching System Engineering and Technological Research Center, Zhengzhou
    450002, China
    不详
    050000, China
    不详
    450052, China
    Tongxin Xuebao, 11
  • [28] Analysis of network traffic features for anomaly detection
    Iglesias, Felix
    Zseby, Tanja
    MACHINE LEARNING, 2015, 101 (1-3) : 59 - 84
  • [29] Three Levels Network Analysis for Anomaly Detection
    Zarpelao, Bruno B.
    Mendes, Leonardo S.
    Proenca, Mario L., Jr.
    Rodrigues, Joel J. P. C.
    2009 INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS, 2009, : 281 - +
  • [30] Analysis of network traffic features for anomaly detection
    Félix Iglesias
    Tanja Zseby
    Machine Learning, 2015, 101 : 59 - 84