A Method for Detecting Wide-scale Network Traffic Anomalies

Minghua Wang · ZTE communications · 2007

Network traffic anomalies and significant changes in the network traffic are unusual. The reason for network anomalies are local security events such as network flashing, Distributed Denial of Service (DDoS) and large-scale network scanning, as well as global security events such as anomalies in routing. It is very important for Computer Security Incident Response Teams (CSIRTs) to detect and analyze network anomalies. Anomalies are detected from large amounts of high-dimensional noise-rich data, which, because of their huge number, make anomaly detection very difficult. This paper proposes a general method based on Principal Component Analysis (PCA) to analyze network anomalies. The method divides the traffic matrix into normal subspace and anomalous subspace, maps the traffic vector into normal subspace, gets the distance from detected vector to average normal vector, and detects anomalies based on that distance.

Read the paper · More papers on PaperTik