Anomaly Detection in Network Traffic Traces Using Latent Dirichlet Allocation

Benjamin David Newton · 2012

The detection of anomalies in network traffic can assist network operators in controlling and securing computer networks. Latent Dirichlet Allocation can be applied to com- puter network traffic, where word counts are replaced with packet counts, and documents, with user sessions. I describe the processing of network traces collected at UNC, and the results of running LDA on these traces. The resulting model can be used to detect anomalies in other network traces on the UNC network. Variational inference is run on a second trace, and three anomalies are detected and analyzed. A simulated Denial of Service Attack is also detected by the model.

Read the paper · More papers on PaperTik