Classification of periodic arrivals in event time data for filtering computer network traffic

被引:4
|
作者
Passino, Francesco Sanna [1 ]
Heard, Nicholas A. [1 ]
机构
[1] Imperial Coll London, Dept Math, 180 Queens Gate, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Circular statistics; Network flow data; Mixture modelling; Periodic arrival times; Periodicity detection; Statistical cyber-security; Wrapped normal; CHAIN MONTE-CARLO;
D O I
10.1007/s11222-020-09943-9
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Periodic patterns can often be observed in real-world event time data, possibly mixed with non-periodic arrival times. For modelling purposes, it is necessary to correctly distinguish the two types of events. This task has particularly important implications in computer network security; there, separating automated polling traffic and human-generated activity in a computer network is important for building realistic statistical models for normal activity, which in turn can be used for anomaly detection. Since automated events commonly occur at a fixed periodicity, statistical tests using Fourier analysis can efficiently detect whether the arrival times present an automated component. In this article, sequences of arrival times which contain automated events are further examined, to separate polling and non-periodic activity. This is first achieved using a simple mixture model on the unit circle based on the angular positions of each event time on the p-clock, where p represents the main periodicity associated with the automated activity; this model is then extended by combining a second source of information, the time of day of each event. Efficient implementations exploiting conjugate Bayesian models are discussed, and performance is assessed on real network flow data collected at Imperial College London.
引用
收藏
页码:1241 / 1254
页数:14
相关论文
共 50 条
  • [11] Promising new Techniques for Computer Network Traffic Classification: A Survey
    Konopa, Michal
    Fesl, Jan
    Janecek, Jan
    2020 10TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER INFORMATION TECHNOLOGIES (ACIT), 2020, : 418 - 421
  • [12] Dynamic Forecasting of Traffic Event Duration in Istanbul: A Classification Approach with Real-Time Data Integration
    Ulu, Mesut
    Turkan, Yusuf Sait
    Menguc, Kenan
    Namli, Ersin
    Kucukdeniz, Tarik
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 80 (02): : 2259 - 2281
  • [13] Dual-Attention-Guided Traffic Event Video Classification Network
    Liu, Chunsheng
    Hao, Penghui
    Chang, Faliang
    Zhou, Jun
    Liu, Zehao
    PROCEEDINGS OF THE 2024 3RD INTERNATIONAL SYMPOSIUM ON INTELLIGENT UNMANNED SYSTEMS AND ARTIFICIAL INTELLIGENCE, SIUSAI 2024, 2024, : 149 - 153
  • [14] Filtering mislabeled data for improving time series classification
    Pelletier, C.
    Valero, S.
    Inglada, J.
    Dedieu, G.
    Champion, N.
    2017 9TH INTERNATIONAL WORKSHOP ON THE ANALYSIS OF MULTITEMPORAL REMOTE SENSING IMAGES (MULTITEMP), 2017,
  • [15] Encrypted Network Traffic Classification: A data driven approach
    Zhang, Zhongkai
    Liu, Lei
    Lu, Xudong
    Yan, Zhongmin
    Li, Hui
    2020 IEEE INTL SYMP ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, INTL CONF ON BIG DATA & CLOUD COMPUTING, INTL SYMP SOCIAL COMPUTING & NETWORKING, INTL CONF ON SUSTAINABLE COMPUTING & COMMUNICATIONS (ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM 2020), 2020, : 706 - 712
  • [16] KALMAN FILTERING OF TRAFFIC FLUCTUATIONS FOR REAL-TIME NETWORK MANAGEMENT
    CHEMOUIL, P
    FILIPIAK, J
    ANNALES DES TELECOMMUNICATIONS-ANNALS OF TELECOMMUNICATIONS, 1989, 44 (11-12): : 633 - 640
  • [17] Using of Time Characteristics in Data Flow for Traffic Classification
    Piskac, Pavel
    Novotny, Jiri
    MANAGING THE DYNAMICS OF NETWORKS AND SERVICES, 2011, 6734 : 173 - 176
  • [18] Filtering and windowing mobile traffic time series for territorial land use classification
    Calegari, Gloria Re
    Carlino, Emanuela
    Peroni, Diego
    Celino, Irene
    COMPUTER COMMUNICATIONS, 2016, 95 : 15 - 28
  • [19] An innovative approach for real-time network traffic classification
    Dias, Klenilmar Lopes
    Pongelupe, Mateus Almeida
    Caminhas, Walmir Matos
    de Errico, Luciano
    COMPUTER NETWORKS, 2019, 158 : 143 - 157
  • [20] Featuring Real-Time imbalanced network traffic classification
    Si Saber, Meriem Amina
    Bayati, Abdolkhalegh
    Nguyen, Kim Khoa
    Cheriet, Mohamed
    IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 840 - 846