Two‐stage selective sampling for anomaly detection: analysis and evaluation
Georgios Androulidakis, Symeon Papavassiliou · Security and Communication Networks · 2010
Abstract Sampling has become an essential component of scalable Internet traffic monitoring and anomaly detection. This paper emphasizes on the analysis and evaluation of the impact of two‐stage sampling (TSS) techniques on network anomaly detection. Through the positive exploitation of the fact that sampled traffic is an incomplete and simultaneously biased approximation of the underlying traffic trace, we propose and analyze an enhanced two‐stage selective sampling approach, where an intelligent flow‐based sampling method that focuses on the selection of small flows that are usually the source of malicious traffic, is adopted. The performance evaluation of the impact of TSS on the anomaly detection process is achieved through the use and application of an entropy‐based anomaly detection method on a packet trace with data that has been collected from a real operational university campus network. The corresponding results demonstrate that the proposed approach improves and favors anomaly detection effectiveness, while at the same time reduces the number of sampled data, and in most cases achieves to even outperform the corresponding results of the unsampled case. Copyright © 2010 John Wiley & Sons, Ltd.