ADAM: A Practical Approach for Detecting Network Anomalies Using PCA
Arshad Ali, Modood Ahmad Khan, Saeed Eftekhar Azam, Hamna Bukhari, Waqar Mahmood · 2004
Anomalies are abnormal behaviors that can arise in any network. This paper presents a practical statistical approach for anomaly detection, analyzing various network related parameters. Our approach ADAM (Anomaly Detection and Analysis Measures), initially uses two parameters i.e. average available bandwidth (ABW) and average round-trip time (AvgRTT). We analyze samples of these two parameters by collecting randomly changing values of these parameters periodically from various remote locations around the world. Our proposed algorithm performs rigorous statistical calculations on these samples. Passing collected data to PCA (Principal Component Analysis) algorithm, which performs separation of link traffic into disjoint normal and anomalous subspaces. We compared our anomaly detection approach with the existing commercial and open-source tools that requires behavior-based and signatures-based detection respectively.