Network Anomaly Traffic Detection Based on IP Monitoring and Non-Gaussian Statistics

Quanyuan Wu · Computer Engineering and Science · 2009

To ensure the security of network and information systems,it is necessary to monitor the network continually and detect the network anomaly (worm outbreaks,DDoS,…) traffic in time,and then effectively support the dynamic,quantitative risk assessment and active defence.Therefore,this paper presents a network anomaly traffic detection method (IPM-NGSD) using IP monitoring and non-Gaussian statistics.This method contains two key segments: frequent IP DB (FIPD) and non-Gaussian statistics modeling.The first segment promptly diffluences the network traffic into frequent and infrequent IP traffic:S0 and S1,by using the Bloom filter technique and FIPD.The second segment first extracts the profile values of non-Gaussian distribution at different aggregation levels for S0 and S1:Porfile0 and Porfile1,and then computes the statistical distance between them to detect anomalies. By a theoretical analysis and two statistical experiments,we confirm the validity of IPM-NGSD:it can prompt and accurately detect both short-lived burst and long-lasting low-intensity network attack traffic,without any prior knowledge of the targeted traffic.

Read the paper · More papers on PaperTik