Classification of periodic arrivals in event time data for filtering computer network traffic

被引:0
|
作者
Francesco Sanna Passino
Nicholas A. Heard
机构
[1] Imperial College London,Department of Mathematics
来源
Statistics and Computing | 2020年 / 30卷
关键词
Circular statistics; Network flow data; Mixture modelling; Periodic arrival times; Periodicity detection; Statistical cyber-security; Wrapped normal;
D O I
暂无
中图分类号
学科分类号
摘要
Periodic patterns can often be observed in real-world event time data, possibly mixed with non-periodic arrival times. For modelling purposes, it is necessary to correctly distinguish the two types of events. This task has particularly important implications in computer network security; there, separating automated polling traffic and human-generated activity in a computer network is important for building realistic statistical models for normal activity, which in turn can be used for anomaly detection. Since automated events commonly occur at a fixed periodicity, statistical tests using Fourier analysis can efficiently detect whether the arrival times present an automated component. In this article, sequences of arrival times which contain automated events are further examined, to separate polling and non-periodic activity. This is first achieved using a simple mixture model on the unit circle based on the angular positions of each event time on the p-clock, where p represents the main periodicity associated with the automated activity; this model is then extended by combining a second source of information, the time of day of each event. Efficient implementations exploiting conjugate Bayesian models are discussed, and performance is assessed on real network flow data collected at Imperial College London.
引用
收藏
页码:1241 / 1254
页数:13
相关论文
共 50 条
  • [1] Classification of periodic arrivals in event time data for filtering computer network traffic
    Passino, Francesco Sanna
    Heard, Nicholas A.
    STATISTICS AND COMPUTING, 2020, 30 (05) : 1241 - 1254
  • [2] Filtering automated polling traffic in computer network flow data
    Heard, Nicholas
    Rubin-Delanchy, Patrick
    Lawson, Daniel
    2014 IEEE JOINT INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (JISIC), 2014, : 268 - 271
  • [3] Periodic Time Series Data Classification By Deep Neural Network
    Zhang, Haolong
    Nayak, Amit
    Lu, Haoye
    2019 26TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2019, : 319 - 323
  • [4] IoT Event Classification Based on Network Traffic
    Charyyev, Batyr
    Gunes, Mehmet Hadi
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 854 - 859
  • [5] Automotive Data Traffic Filtering and Classification with Finding Errors
    Roguljic, Luka
    Vranjes, Mario
    Milosevic, Milena
    Samardzija, Dragan
    2020 ZOOMING INNOVATION IN CONSUMER TECHNOLOGIES CONFERENCE (ZINC), 2020, : 201 - 206
  • [6] Network traffic classification based on periodic behavior detection
    Koumar, Josef
    Cejka, Tomas
    2022 18TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM 2022): INTELLIGENT MANAGEMENT OF DISRUPTIVE NETWORK TECHNOLOGIES AND SERVICES, 2022,
  • [7] Method of data cleaning for network traffic classification
    Wang, R.-Y. (rywang@scut.edu.cn), 1600, Beijing University of Posts and Telecommunications (21):
  • [8] Network traffic classification for data fusion: A survey
    Zhao, Jingjing
    Jing, Xuyang
    Yan, Zheng
    Pedrycz, Witold
    INFORMATION FUSION, 2021, 72 : 22 - 47
  • [9] Method of data cleaning for network traffic classification
    WANG Ruo-yu
    LIU Zhen
    ZHANG Ling
    The Journal of China Universities of Posts and Telecommunications, 2014, (03) : 35 - 45
  • [10] Method of data cleaning for network traffic classification
    WANG Ruo-yu
    LIU Zhen
    ZHANG Ling
    The Journal of China Universities of Posts and Telecommunications, 2014, 21 (03) : 35 - 45