When randomness improves the anomaly detection performance

Christian Callegari, Loris Gazzarrini, Stefano Giordano, Michele Pagano, Teresa Pepe · 2010

The increasing number of network attacks causes growing problems for network operators and users. Thus, detecting anomalous traffic is of primary interest in IP networks management. The problem has been faced by many researchers, but still remains an open field, since a general solution has not been found yet. In this paper we want to demonstrate as the performance of well-known methods for network anomaly detection can be improved, by performing a random aggregation of the data, before looking for the anomalies. In more detail, we show that, in two distinct cases (chosen as representative of the state-of-the-art in the field) the use of the sketches strongly improves the achieved performance.

Read the paper · More papers on PaperTik