Proposal and comparison of network anomaly detection based on long-memory statistical models
Tomasz Andrysiak, Łukasz Saganowski, Michał Choraś, Rafał Kozik · Logic Journal of IGPL · 2016
In this article, we present network anomaly detection system based on long memory statistical models. In order to determine whether the analysed time series are characterized by the long memory, they underwent tests with the use of the local Whittles estimator. The tests were performed over three diverse statistic approaches described as ARFIMA, A-FIGARCH and MIDAS. The choice of optimal values of model parameters is performed on the basis of the information criteria representing a compromise between consistency model and the size of its error of estimates. In the presented method, we propose to use statistical relationships between predicted and original network traffic to determine if the examined trace is normal or attacked. Efficiency of our method is verified with the use of extended set of benchmark test real traces. The experimental results confirm flexibility and effectiveness of the presented solutions.