Anomaly detection technique oriented to TCP flow

Wenhua Jiao · Journal of Civil Aviation University of China · 2014

In order to solve the problem that network-flow anomaly detection cannot distinguish between mutations in normal and abnormal traffic flow, an anomaly detection technique oriented to TCP flow is presented. Using method of summary data structure, this model calculates the Hurst parameter and TCP packet integrity to discover the network anomalies. Not only can it achieve a summary of large-scale data storage to improve the efficiency, but also realize the purpose to distinguish between the burst traffic with abnormal tratfic flow.Experimental results show that this method has high detection rate and low false detection rate, it can be better used in network anomaly detection.

Read the paper · More papers on PaperTik