Traffic Anomaly Detection and Cause Identification Using Flow-Level Measurements
Gerhard Münz · mediaTUM – the media and publications repository of the Technical University Munich (Technical University Munich) · 2010
sified according to their relevance from the point of view of the network administrator.The evaluation shows that the combination of exponential smoothing and Shewhart control chart is appropriate for detecting certain kinds of relevant anomalies without requiring much adaptation or parameter tuning.Multi-metric anomaly detection using batch-mode PCA and T 2 control chart yields a very large proportion of relevant alarms, yet at the cost of increased complexity and with a need for training data.In this context, robust M-estimators are useful to reduce the bias caused by outliers in the training data.As an important result, the choice of traffic metrics and the analyzed part of traffic turn out to have a large influence on which kinds of anomalies can be detected.Just like most traffic anomaly detection approaches, the presented methods are limited to the detection of traffic anomalies but do not provide any information about their causes.Without such information, however, anomaly notifications are quite useless for the network administrator because he cannot assess the relevance of the reported events, nor can he decide on any appropriate reaction.Conducting a manual investigation of the original flow records allows identifying the responsible flows in most cases, yet this detective work is very time-consuming and therefore cannot be afforded.As a solution to this problem, we present a couple of algorithms enabling the automated identification of frequent anomaly causes which are of potential interest for the network administrator, such as scanning activities and brute-force password guessing.With these algorithms, most of the relevant anomalies can be examined without requiring any manual intervention.Altogether, the methods and algorithms presented in this dissertation provide a feasible solution to detect traffic anomalies and to identify their causes.In addition, they can be easily deployed in high-speed networks.