A robust anomaly detection method using a constant false alarm rate approach

被引:0
|
作者
Basil AsSadhan
Rayan AlShaalan
Diab M. Diab
Abraham Alzoghaiby
Saleh Alshebeili
Jalal Al-Muhtadi
Hesham Bin-Abbas
Fathi Abd El-Samie
机构
[1] King Saud University,Department of Electrical Engineering
[2] King Saud University,Center of Excellence in Information Assurance (CoEIA)
[3] Communications and Information Technology Commission,Department of Computer Science
[4] King Saud University,KACST
[5] King Abdulaziz City for Science and Technology,TIC in RF and Photonics for the e
[6] King Saud University,Society (RFTONICS)
[7] Menoufia University,Department of Electronics and Electrical Communications Engineering
来源
关键词
Anomaly detection; Constant false alarm rate; Cross-correlation; Volume-based anomalies;
D O I
暂无
中图分类号
学科分类号
摘要
With the rapid growth of information and communication technologies, the number of security threats in computer networks is substantially increasing; thus, the development of more proactive security warning measures is required. In this work, we propose a new anomaly detection method that operates by decomposing TCP traffic into control and data planes, which exhibit similar behaviors in the absence of attacks. The proposed method exploits the statistics of the cross-correlation function of the two planes traffic and the constant false alarm rate (CFAR) scheme for detecting anomalies of the underlying network traffic. Both the fixed and adaptive thresholding schemes are implemented. The adaptive thresholding is setup by adjusting the value of the threshold in accordance with the local statistics of the cross-correlation function of the two planes traffic. We evaluate the performance of the proposed method by analyzing the real traffic captured from a deployed network and traffic obtained from other publicly available datasets; we focus on TCP traffic with three different aggregated count features: packet count, IP address count, and port count sequences. Although both the fixed and adaptive thresholding schemes perform well and detect the presence of a distributed denial-of-service efficiently. The adaptive thresholding scheme is more reliable because it detects anomalies as they start.
引用
收藏
页码:12727 / 12750
页数:23
相关论文
共 50 条
  • [31] A CONSTANT-FALSE-ALARM-RATE ALGORITHM
    BUNCH, JR
    FIERRO, RD
    LINEAR ALGEBRA AND ITS APPLICATIONS, 1992, 172 : 231 - 241
  • [32] DISPERSIVE CONSTANT FALSE ALARM RATE RECEIVER
    WARD, HR
    PROCEEDINGS OF THE INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS, 1972, 60 (06): : 735 - &
  • [33] AN ADAPTIVE CONSTANT FALSE ALARM DETECTION METHOD BASED ON BACKGROUND DISCRIMINATION
    Wang, Weihao
    Zong, Zhulin
    Feng, Bin
    IGARSS 2023 - 2023 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, 2023, : 6133 - 6136
  • [34] Research on Constant False Alarm Rate Detection Technique for Ship in SAR Image
    Meng, Xiangwei
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2024, 46 (09): : 3739 - 3748
  • [35] Signature adaptive target detection and threshold selection for constant false alarm rate
    Crosby, F
    JOURNAL OF ELECTRONIC IMAGING, 2005, 14 (03) : 1 - 10
  • [36] An Improved Constant False Alarm Rate Algorithm for Target Detection in SAR Image
    Li Chengmao
    Chen Yongming
    2010 ETP/IITA CONFERENCE ON TELECOMMUNICATION AND INFORMATION (TEIN 2010), 2010, : 133 - +
  • [37] New matrix constant false alarm rate detectors for radar target detection
    Zhao, Wenjing
    Zou, Deyue
    Liu, Wenlong
    Jin, Minglu
    JOURNAL OF ENGINEERING-JOE, 2019, 2019 (19): : 5597 - 5601
  • [38] Constant false alarm rate detection of pipeline leakage based on acoustic sensors
    An, Guorui
    Huang, Zuheng
    Li, Yanbing
    SCIENTIFIC REPORTS, 2023, 13 (01)
  • [39] Wavelength-resolution SAR Change Detection with Constant False Alarm Rate
    Vu, Viet T.
    Pettersson, Mats
    Gomes, Natanael R.
    Dammert, Patrik
    Hellsten, Hans
    2017 IEEE RADAR CONFERENCE (RADARCONF), 2017, : 1504 - 1508
  • [40] Hypothesis Testing and Decision Making: Constant-False-Alarm-Rate Detection
    Sevgi, L.
    IEEE ANTENNAS AND PROPAGATION MAGAZINE, 2009, 51 (03) : 218 - 224