Sketch based Anomaly Detection, Identification and Performance Evaluation

Patrice Abry, Pierre Borgnat, Guillaume Dewaele · 2007

An anomaly detection procedure is defined and its sta-tistical performance are carefully quantified. It is based on a non Gaussian modeling of the marginal distributions of random projections (sketches) of traffic aggregated jointly at different levels (multiresolution). To evaluate false neg-ative vs. false positive in a controlled, reproducible and documented framework, we apply the detection procedure to traffic time-series from our self-made anomaly database. It is obtained by performing DDoS-type attacks, using real-world attack tools, over a real operational network. Also, we illustrate that combining sketches enables us to identify the target IP destination address and faulty packets hence opening the track to attack mitigation. 1 Motivations and Contributions

Read the paper · More papers on PaperTik