Autonomous profile-based anomaly detection system using principal component analysis and flow analysis

被引:33
|
作者
Fernandes, Gilberto, Jr. [1 ]
Rodrigues, Joel J. P. C. [1 ,2 ]
Proenca, Mario Lemes, Jr. [3 ]
机构
[1] Univ Beira Interior, Inst Telecomunicacoes, Covilha, Portugal
[2] Univ Fortaleza UNIFOR, Fortaleza, Ceara, Brazil
[3] State Univ Londrina UEL, Dept Comp Sci, Londrina, Brazil
关键词
Network management; Traffic characterization; Anomaly detection; Principal component analysis; Flows; FEATURE-SELECTION; PCA; ROBUST;
D O I
10.1016/j.asoc.2015.05.019
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Different techniques and methods have been widely used in the subject of automatic anomaly detection in computer networks. Attacks, problems and internal failures when not detected early may badly harm an entire Network system. Thus, an autonomous anomaly detection system based on the statistical method principal component analysis (PCA) is proposed. This approach creates a network profile called Digital Signature of Network Segment using Flow Analysis (DSNSF) that denotes the predicted normal behavior of a network traffic activity through historical data analysis. That digital signature is used as a threshold for volume anomaly detection to detect disparities in the normal traffic trend. The proposed system uses seven traffic flow attributes: bits, packets and number of flows to detect problems, and source and destination IP addresses and Ports, to provides the network administrator necessary information to solve them. Via evaluation techniques performed in this paper using real network traffic data, results showed good traffic prediction by the DSNSF and encouraging false alarm generation and detection accuracy on the detection schema using thresholds. (C) 2015 Elsevier B.V. All rights reserved.
引用
收藏
页码:513 / 525
页数:13
相关论文
共 50 条
  • [21] A novel method for anomaly detection using Beta Hebbian Learning and Principal Component Analysis
    Zayas-Gato, Francisco
    Michelena, Alvaro
    Quintian, Hector
    Jove, Esteban
    Casteleiro-Roca, Jose-Luis
    Leitao, Paulo
    Luis Calvo-Rolle, Jose
    LOGIC JOURNAL OF THE IGPL, 2023, 31 (02) : 390 - 399
  • [22] Magnetic anomaly detection (MAD) of ferromagnetic pipelines using principal component analysis (PCA)
    Sheinker, Arie
    Moldwin, Mark B.
    MEASUREMENT SCIENCE AND TECHNOLOGY, 2016, 27 (04)
  • [24] Probabilistic principal component analysis-based anomaly detection for structures with missing data
    Ma, Zhi
    Yun, Chung-Bang
    Wan, Hua-Ping
    Shen, Yanbin
    Yu, Feng
    Luo, Yaozhi
    STRUCTURAL CONTROL & HEALTH MONITORING, 2021, 28 (05):
  • [25] Anomaly Detection Based on Information Granulation and Principal Component Analysis for Geological Drilling Process
    Huang, Cheng
    Du, Sheng
    Fan, Haipeng
    Wu, Min
    Cao, Weihua
    2024 43RD CHINESE CONTROL CONFERENCE, CCC 2024, 2024, : 2750 - 2755
  • [26] Randomized subspace-based robust principal component analysis for hyperspectral anomaly detection
    Sun, Weiwei
    Yang, Gang
    Li, Jialin
    Zhang, Dianfa
    JOURNAL OF APPLIED REMOTE SENSING, 2018, 12 (01)
  • [27] Profile-based, Load-Independent Anomaly Detection and Analysis in Performance Regression Testing of Software Systems
    Ghaith, Shadi
    Wang, Miao
    Perry, Philip
    Murphy, John
    PROCEEDINGS OF THE 17TH EUROPEAN CONFERENCE ON SOFTWARE MAINTENANCE AND REENGINEERING (CSMR 2013), 2013, : 379 - 383
  • [28] Profile-based authorship analysis
    Dunn, Jonathan
    Argamon, Shlomo
    Rasooli, Amin
    Kumar, Geet
    DIGITAL SCHOLARSHIP IN THE HUMANITIES, 2016, 31 (04) : 689 - 710
  • [29] FILTERING CLIMATIC ANOMALY FIELDS USING PRINCIPAL COMPONENT ANALYSIS
    PERRY, AH
    TRANSACTIONS OF THE INSTITUTE OF BRITISH GEOGRAPHERS, 1970, (50) : 55 - 72
  • [30] Soil Clustering and Anomaly Detection Based on EPBM Data Using Principal Component Analysis and Local Outlier Factor
    Apoji, Dayu
    Soga, Kenichi
    GEO-RISK 2023: DEVELOPMENTS IN RELIABILITY, RISK, AND RESILIENCE, 2023, 346 : 1 - 11