A Hybrid Approach to Detect Traffic Anomalies in Large-Scale Data Networks

Xin Sun, Fu-Shing Sun · 2016

We present our thoughts on the design of a novel hybrid system for detecting anomalous traffic in large-scale, policy-rich data networks. A key innovation in our approach is the combination of static configuration analysis and dynamic traffic analytics. More specifically, we will first develop abstractions and mathematical models to formally model the network and security configurations to statically check for violation of network-wide invariants, which are potential security vulnerabilities. We will then develop dynamic data analytic techniques to analyze traffic in real-time and detect anomalous traffic patterns that may be exploiting the security vulnerabilities in the network. The results from the static analysis will be used to assist and guide the dynamic traffic analytics to optimize resource allocation and minimize false positives.

Read the paper · More papers on PaperTik