NEAR — Network extractor of anomaly records or traffic split-counting for anomaly detection
Florin Vancea, Codruţa Vancea · 2013
The availability of network communications may be affected or even disrupted by malicious actions or by unexpected usage conditions. The good health of systems connected to the network (or lack thereof) may also reflect on network usage patterns. In order to maintain proper functionality for a significantly large network domain, automated or semi-automated methods of anomaly detection are required and several systems have been developed so far. This paper presents NEAR, the feature collection part of such a system, aiming to detect abnormal conditions by collecting relevant traffic features in key points of the network before analyzing them using signal processing methods.