Autonomous profile-based anomaly detection system using principal component analysis and flow analysis

被引:33
|
作者
Fernandes, Gilberto, Jr. [1 ]
Rodrigues, Joel J. P. C. [1 ,2 ]
Proenca, Mario Lemes, Jr. [3 ]
机构
[1] Univ Beira Interior, Inst Telecomunicacoes, Covilha, Portugal
[2] Univ Fortaleza UNIFOR, Fortaleza, Ceara, Brazil
[3] State Univ Londrina UEL, Dept Comp Sci, Londrina, Brazil
关键词
Network management; Traffic characterization; Anomaly detection; Principal component analysis; Flows; FEATURE-SELECTION; PCA; ROBUST;
D O I
10.1016/j.asoc.2015.05.019
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Different techniques and methods have been widely used in the subject of automatic anomaly detection in computer networks. Attacks, problems and internal failures when not detected early may badly harm an entire Network system. Thus, an autonomous anomaly detection system based on the statistical method principal component analysis (PCA) is proposed. This approach creates a network profile called Digital Signature of Network Segment using Flow Analysis (DSNSF) that denotes the predicted normal behavior of a network traffic activity through historical data analysis. That digital signature is used as a threshold for volume anomaly detection to detect disparities in the normal traffic trend. The proposed system uses seven traffic flow attributes: bits, packets and number of flows to detect problems, and source and destination IP addresses and Ports, to provides the network administrator necessary information to solve them. Via evaluation techniques performed in this paper using real network traffic data, results showed good traffic prediction by the DSNSF and encouraging false alarm generation and detection accuracy on the detection schema using thresholds. (C) 2015 Elsevier B.V. All rights reserved.
引用
收藏
页码:513 / 525
页数:13
相关论文
共 50 条
  • [1] Anomaly Detection Based on Kernel Principal Component and Principal Component Analysis
    Wang, Wei
    Zhang, Min
    Wang, Dan
    Jiang, Yu
    Li, Yuliang
    Wu, Hongda
    COMMUNICATIONS, SIGNAL PROCESSING, AND SYSTEMS, 2019, 463 : 2222 - 2228
  • [2] Anomaly detection based on kernel principal component and principal component analysis
    Wang, Wei
    Zhang, Min
    Wang, Dan
    Jiang, Yu
    Li, Yuliang
    Wu, Hongda
    Lecture Notes in Electrical Engineering, 2019, 463 : 2222 - 2228
  • [4] Anomaly Detection of Spacecraft Attitude Control System Based on Principal Component Analysis
    Feng Bingqing
    Hu Shaolin
    Li Chuan
    Miao Yangfan
    2017 29TH CHINESE CONTROL AND DECISION CONFERENCE (CCDC), 2017, : 1220 - 1225
  • [5] A robust anomaly detection algorithm based on principal component analysis
    Huang, Yingkun
    Jin, Weidong
    Yu, Zhibin
    Li, Bing
    INTELLIGENT DATA ANALYSIS, 2021, 25 (02) : 249 - 263
  • [6] Anomaly Detection in POSTFIX mail log using Principal Component Analysis
    Cao-Phi Tran
    Duc-Khanh Tran
    PROCEEDINGS OF 2018 10TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE), 2018, : 107 - 112
  • [7] Actor Model Anomaly Detection Using Kernel Principal Component Analysis
    Wang, Chunze
    Wang, Jing
    Wang, Chun
    Shen, Qiwei
    NEURAL INFORMATION PROCESSING (ICONIP 2018), PT IV, 2018, 11304 : 545 - 554
  • [8] Anomaly detection model of user behavior based on principal component analysis
    Bi, Meng
    Xu, Jian
    Wang, Mo
    Zhou, Fucai
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2016, 7 (04) : 547 - 554
  • [9] Anomaly detection model of user behavior based on principal component analysis
    Meng Bi
    Jian Xu
    Mo Wang
    Fucai Zhou
    Journal of Ambient Intelligence and Humanized Computing, 2016, 7 : 547 - 554
  • [10] GPR Anomaly Detection with Robust Principal Component Analysis
    Masarik, Matthew P.
    Burns, Joseph
    Thelen, Brian T.
    Kelly, Jack
    Havens, Timothy C.
    DETECTION AND SENSING OF MINES, EXPLOSIVE OBJECTS, AND OBSCURED TARGETS XX, 2015, 9454