Autonomous profile-based anomaly detection system using principal component analysis and flow analysis

被引:33
|
作者
Fernandes, Gilberto, Jr. [1 ]
Rodrigues, Joel J. P. C. [1 ,2 ]
Proenca, Mario Lemes, Jr. [3 ]
机构
[1] Univ Beira Interior, Inst Telecomunicacoes, Covilha, Portugal
[2] Univ Fortaleza UNIFOR, Fortaleza, Ceara, Brazil
[3] State Univ Londrina UEL, Dept Comp Sci, Londrina, Brazil
关键词
Network management; Traffic characterization; Anomaly detection; Principal component analysis; Flows; FEATURE-SELECTION; PCA; ROBUST;
D O I
10.1016/j.asoc.2015.05.019
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Different techniques and methods have been widely used in the subject of automatic anomaly detection in computer networks. Attacks, problems and internal failures when not detected early may badly harm an entire Network system. Thus, an autonomous anomaly detection system based on the statistical method principal component analysis (PCA) is proposed. This approach creates a network profile called Digital Signature of Network Segment using Flow Analysis (DSNSF) that denotes the predicted normal behavior of a network traffic activity through historical data analysis. That digital signature is used as a threshold for volume anomaly detection to detect disparities in the normal traffic trend. The proposed system uses seven traffic flow attributes: bits, packets and number of flows to detect problems, and source and destination IP addresses and Ports, to provides the network administrator necessary information to solve them. Via evaluation techniques performed in this paper using real network traffic data, results showed good traffic prediction by the DSNSF and encouraging false alarm generation and detection accuracy on the detection schema using thresholds. (C) 2015 Elsevier B.V. All rights reserved.
引用
收藏
页码:513 / 525
页数:13
相关论文
共 50 条
  • [31] Underwater moving target detection using online robust principal component analysis and multimodal anomaly detection
    Zou, Shaofeng
    Wang, Xuyang
    Yuan, Tao
    Zeng, Kaihui
    Li, Guolin
    Xie, Xiang
    JOURNAL OF THE ACOUSTICAL SOCIETY OF AMERICA, 2025, 157 (01): : 122 - 136
  • [32] Sensor Failure Detection of FASSIP System using Principal Component Analysis
    Sudarno
    Juarsa, Mulya
    Santosa, Kussigit
    Deswandri
    Sunaryo, Geni Rina
    INTERNATIONAL CONFERENCE ON NUCLEAR ENERGY TECHNOLOGIES AND SCIENCES (ICONETS 2017), 2018, 962
  • [33] Intrusion detection using principal component analysis
    Bouzida, Y
    Gombault, S
    7TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL IX, PROCEEDINGS: COMPUTER SCIENCE AND ENGINEERING: II, 2003, : 98 - 103
  • [34] Improved principal component analysis for anomaly detection: Application to an emergency department
    Harrou, Fouzi
    Kadri, Farid
    Chaabane, Sondes
    Tahon, Christian
    Sun, Ying
    COMPUTERS & INDUSTRIAL ENGINEERING, 2015, 88 : 63 - 77
  • [35] Anomaly Detection via Over-Sampling Principal Component Analysis
    Yeh, Yi-Ren
    Lee, Zheng-Yi
    Lee, Yuh-Jye
    NEW ADVANCES IN INTELLIGENT DECISION TECHNOLOGIES, 2009, 199 : 449 - 458
  • [36] Fault detection of flywheel system based on clustering and principal component analysis
    Wang Rixin
    Gong Xuebing
    Xu Minqiang
    Li Yuqing
    Chinese Journal of Aeronautics, 2015, (06) : 1676 - 1688
  • [37] Network Anomaly Detection Using Autonomous System Flow Aggregates
    Johnson, Thienne
    Lazos, Loukas
    2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 544 - 550
  • [38] Fault detection of flywheel system based on clustering and principal component analysis
    Wang Rixin
    Gong Xuebing
    Xu Minqiang
    Li Yuqing
    CHINESE JOURNAL OF AERONAUTICS, 2015, 28 (06) : 1676 - 1688
  • [39] Fault detection of flywheel system based on clustering and principal component analysis
    Wang Rixin
    Gong Xuebing
    Xu Minqiang
    Li Yuqing
    Chinese Journal of Aeronautics, 2015, 28 (06) : 1676 - 1688
  • [40] Unsupervised anomaly detection based on principal components analysis
    Guan, Jian
    Liu, Da-Xin
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2004, 41 (09): : 1474 - 1480