Network Anomaly Detection Using Time Series Analysis

Qingtao Wu, Zhiqing Shao · 2005

This paper presents a method of detecting network anomalies by analyzing the abrupt change of time series data obtained from Management Information Base (MIB) variables. The method applies the Auto- Regressive (AR) process to model the abrupt change of time series data, and performs sequential hypothesis test to detect the anomalies. With time correlation and location correlation, the method determines not only the presence of anomalous activity, but also its occurring time and location. The experimental results show that the proposed method performs well in detecting the traffic-related Anomalies

Read the paper · More papers on PaperTik