A robust anomaly detection method using a constant false alarm rate approach

被引:0
|
作者
Basil AsSadhan
Rayan AlShaalan
Diab M. Diab
Abraham Alzoghaiby
Saleh Alshebeili
Jalal Al-Muhtadi
Hesham Bin-Abbas
Fathi Abd El-Samie
机构
[1] King Saud University,Department of Electrical Engineering
[2] King Saud University,Center of Excellence in Information Assurance (CoEIA)
[3] Communications and Information Technology Commission,Department of Computer Science
[4] King Saud University,KACST
[5] King Abdulaziz City for Science and Technology,TIC in RF and Photonics for the e
[6] King Saud University,Society (RFTONICS)
[7] Menoufia University,Department of Electronics and Electrical Communications Engineering
来源
关键词
Anomaly detection; Constant false alarm rate; Cross-correlation; Volume-based anomalies;
D O I
暂无
中图分类号
学科分类号
摘要
With the rapid growth of information and communication technologies, the number of security threats in computer networks is substantially increasing; thus, the development of more proactive security warning measures is required. In this work, we propose a new anomaly detection method that operates by decomposing TCP traffic into control and data planes, which exhibit similar behaviors in the absence of attacks. The proposed method exploits the statistics of the cross-correlation function of the two planes traffic and the constant false alarm rate (CFAR) scheme for detecting anomalies of the underlying network traffic. Both the fixed and adaptive thresholding schemes are implemented. The adaptive thresholding is setup by adjusting the value of the threshold in accordance with the local statistics of the cross-correlation function of the two planes traffic. We evaluate the performance of the proposed method by analyzing the real traffic captured from a deployed network and traffic obtained from other publicly available datasets; we focus on TCP traffic with three different aggregated count features: packet count, IP address count, and port count sequences. Although both the fixed and adaptive thresholding schemes perform well and detect the presence of a distributed denial-of-service efficiently. The adaptive thresholding scheme is more reliable because it detects anomalies as they start.
引用
收藏
页码:12727 / 12750
页数:23
相关论文
共 50 条
  • [42] Induction Machine Faults Detection based on a Constant False Alarm Rate Detector
    Trachi, Youness
    Elbouchikhi, Elhoussin
    Choqueuse, Vincent
    Wang, Tianzhen
    Benbouzid, Mohamed
    PROCEEDINGS OF THE IECON 2016 - 42ND ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2016, : 6359 - 6363
  • [43] Constant false alarm rate detection of pipeline leakage based on acoustic sensors
    Guorui An
    Zuheng Huang
    Yanbing Li
    Scientific Reports, 13
  • [44] Constant False Alarm Rate Detection of Multicarrier Signals With Periodic Power Boosting
    Karunakaran, Prasanth
    Gerstacker, Wolfgang H.
    IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2018, 4 (02) : 379 - 389
  • [45] Distributed Clutter-Map Constant False Alarm Rate Detection Using Fuzzy Fusion Rules
    Bouchelaghem H.E.
    Hamadouche M.
    Soltani F.
    Baddari K.
    Radioelectronics and Communications Systems, 2019, 62 (01): : 1 - 5
  • [46] Automated threshold selection for a Constant False Alarm Rate
    Stetson, S
    Crosby, F
    DETECTION AND REMEDIATION TECHNOLOGIES FOR MINES AND MINELIKE TARGETS VIII, PTS 1 AND 2, 2003, 5089 : 1383 - 1394
  • [47] A new distributed constant false alarm rate detector
    Amirmehrabi, H
    Viswanathan, R
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1997, 33 (01) : 85 - 97
  • [48] STATISTICAL MODELS FOR CONSTANT FALSE ALARM RATE SHIP DETECTION WITH THE SUBLOOK CORRELATION MAGNITUDE
    Anfinsen, Stian Normann
    Brekke, Camilla
    2012 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM (IGARSS), 2012, : 5626 - 5629
  • [49] Normalized residual-based constant false-alarm rate outlier detection
    Ru, Xiaohu
    Liu, Zheng
    Huang, Zhitao
    Jiang, Wenli
    PATTERN RECOGNITION LETTERS, 2016, 69 : 1 - 7
  • [50] Manifold Adaptation for Constant False Alarm Rate Ship Detection in South African Oceans
    Schwegmann, Colin P.
    Kleynhans, Waldo
    Salmon, Brian P.
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2015, 8 (07) : 3329 - 3337