Flow-based statistical aggregation schemes for network anomaly detection

被引:0
|
作者
Song, Sui [1 ]
Ling, Li [1 ]
Manikopoulo, C. N. [1 ]
机构
[1] New Jersey Inst Technol, Dept Elect Engn, Newark, NJ 07102 USA
关键词
flow; aggregation; neural network classifier; network intrusion detection system;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present a novel Flow-based Statistical Aggregation Schemes (FSAS) for Network Anomaly Detection. An IP flow is a unidirectional series of IP packets of a given protocol, traveling between a source and destination, within a certain period of time. Based on "flow" concept, we developed a flow-based aggregation technique that dramatically reduces the amount of monitoring data and handles high amounts of statistics and packet data. FSSAS sets up flow-based statistical feature vectors and reports to Neural Network Classifier. Neural Classifier uses Back-Propagation networks to classify score metric of each flow. FSAS can detect both bandwidth type DOS and protocol type DOS. Moreover, flow here could be any set of packets sharing certain common property as "flow key". FSAS configures flow flexibly to provide security from network level to application level (IP, TCP, UDP, HTTP, FTP...), and different aggregation schemes, such as server -based, client-based flow. This novel IDS has been evaluated by using DARPA 98 data and CONEX test-bed data. Results show the success in terms of different aggregation schemes for both datasets.
引用
收藏
页码:786 / 791
页数:6
相关论文
共 50 条
  • [21] Flow-based Front Payload Aggregation
    Limmer, Tobias
    Dressler, Falko
    2009 IEEE 34TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2009), 2009, : 1102 - 1109
  • [22] Flow-based anomaly intrusion detection using machine learning model with software defined networking for OpenFlow network
    Satheesh, N.
    Rathnamma, M. V.
    Rajeshkumar, G.
    Sagar, P. Vidya
    Dadheech, Pankaj
    Dogiwal, S. R.
    Velayutham, Priya
    Sengan, Sudhakar
    MICROPROCESSORS AND MICROSYSTEMS, 2020, 79
  • [23] A Novel Hybrid Intrusion Detection Using Flow-Based Anomaly Detection and Cross-Layer Features in Wireless Sensor Network
    Gandhimathi, L.
    Murugaboopathi, G.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2020, 54 (01) : 62 - 69
  • [24] A Novel Hybrid Intrusion Detection Using Flow-Based Anomaly Detection and Cross-Layer Features in Wireless Sensor Network
    L. Gandhimathi
    G. Murugaboopathi
    Automatic Control and Computer Sciences, 2020, 54 : 62 - 69
  • [25] Analyzing Flow-based Anomaly Intrusion Detection using Replicator Neural Networks
    Cordero, Carlos Garcia
    Hauke, Sascha
    Muhlhauser, Max
    Fischert, Mathias
    2016 14TH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2016,
  • [26] Normalizing Flow-Based Probability Distribution Representation Detector for Hyperspectral Anomaly Detection
    Li, Xiaorun
    Yu, Shaoqi
    Chen, Shuhan
    Zhao, Liaoying
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2022, 15 : 4885 - 4896
  • [27] Flow-based Anomaly Detection Using Multilayer Perceptron in Software Defined Networks
    Lai, Yuan-Cheng
    Zhou, Kai-Zhong
    Lin, Si-Ru
    Lo, Nai-Wei
    2019 42ND INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2019, : 1154 - 1158
  • [29] The methods of network traffic statistical anomaly detection based on Network processor
    Yun, Li
    Ge, Renhua
    Li, Jinghua
    IITAW: 2009 THIRD INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY APPLICATIONS WORKSHOPS, 2009, : 54 - +
  • [30] Intrusion Detection Using Flow-Based Analysis of Network Traffic
    David, Jisa
    Thomas, Ciza
    ADVANCES IN NETWORKS AND COMMUNICATIONS, PT II, 2011, 132 : 391 - 399