Improving an SVD-based combination strategy of anomaly detectors for traffic labelling
Johan Mazel, Hiroshi Esaki, Romain Fontugne, Kensuke Fukuda · 2012
Network anomaly detection is a crucial task in traffic monitoring. Tools targeting this particular problematic need to be thoroughly evaluated to assess their efficiency. Such evaluation needs reliable ground truth data to be effective. The goal of the present article is to assist researchers in the evaluation of detectors by providing them with labelled anomaly traffic traces. One of the promising strategies to provide reliable ground truth data is to combine the output of the multiple anomaly detectors with different theoretical background. In this paper, we provide an in-depth analysis of the Singular Value Decomposition (SVD) based combination strategy that has been recently applied to anomaly detectors (MAWILab). This analysis highlights the key drawback of the method to efficiently discriminate the anomalous traffic from the harmless one. We then propose several techniques to overcome this drawback and improve the discrimination power of the combination strategy. Our evaluation using four anomaly detectors and four years of real backbone traffic traces (MAWI) emphasizes the accuracy gain of the proposed techniques over the original study.