Proposal of a new information theory-based technique based on traffic anomaly detection analysis
Antonio Cuadra Sánchez, Javier Aracil, Javier Ramos · International Journal of Parallel Emergent and Distributed Systems · 2015
The change-point detection theory is used to identify abrupt changes in the network traffic. The literature has focused on longitudinal traffic analysis, namely, detecting sudden peak changes, rather than analysing the traffic pattern on a 24 h typical day. As traffic varies throughout the day, it is essential to consider the concrete traffic period in which the anomaly occurs, which is useful for checking interconnection agreements amongst operators, something not possible with traditional sudden peak changes techniques. The aim of this paper is to analyse how the different algorithms behave in detecting changing points inside a typical day profile. We conclude that a combination of the algorithms provides better results than the use of a single one: in low traffic periods the tests of goodness-of-fit best detect changing conditions, while in normal traffic periods (daytime) entropy-based algorithms best detect traffic increases; besides, the statistical control charts complements both of them when detecting very abrupt changes regardless of the traffic load.