Unsupervised Anomaly Detection in Massive Traffic Using S-transform and Renyi Divergence
Sirikarn Pukkawanna · Institutional Repositories DataBase (IRDB) · 2015
The detection of network anomalies is an indispensable component of overall security architecture.As sophisticated attacks grow exponentially, preserving security with signature-based Network Intrusion Detection Systems (NIDS) may not be sufficient because they cannot detect new and unknown attacks.Furthermore, in order to obtain good performance from a signature-based NIDS, a network administrator has to essentially keep updating new accurate signatures to the NIDS's signature database.In this dissertation, we propose two novel network anomaly detection methods: S-transform-based and Rényi divergence-based methods.Both methods do not require the pre-defined signatures of targets and are able to detect unknown and new malicious and disruptive traffic with high accuracy and low false positive rates.The methods' targets include malicious traffic caused by Denial-of-Service (DoS) attacks, Internet worms, scannings, and legitimate traffic that is likely to disrupt networks or devices.This dissertation consists of two main parts.The first part presents the Stransform-based anomaly detection method.Our method uses S-transform to convert a traffic signal (e.g., packet rate) to a time-frequency domain.The method then detects unusual time-frequency behavior caused by anomalies in the timefrequency domain.The major advantage of our method is that it can detect hidden anomalies that cannot be easily seen in the traffic signal (time domain data).We evaluated our method with simulated traffic from the DARPA dataset and real-world backbone traffic from the MAWI dataset.Furthermore, we compared the performance of our method with a popular Wavelet transform-based