Multi-timeline Based Real-time Anomaly Detection in Network Traffic

Kriangkrai Limthong, クリアングライ リムソン, Kriangkrai Limthong · SOKENDAI (Graduate University for Advanced Studies) · 2015

T he volume of traffic in both core and access networks has exponentially increased every year over the past few decades.The computer attacks also have increased in sophisticated techniques to evade existing intrusion detection systems.It is rather difficult for daily network operators and administrators to inspect every single packet or flow for discovering anomalies.Therefore, the need to automatically detect attacks and unusual incidents in computer networks is of crucial importance for nowadays operations.An effective system that could expeditiously detect a broad range of anomalies would enable administrators to prevent serious consequences of anomalies related to network security, availability, or reliability.For over a decade, many researchers have been studying to improve techniques for anomaly detection by proposing and applying plenty of methods from simple to sophisticated ones.Unfortunately, most of the studies are batch processing techniques, and many of them are not fairly flexible to detect a vast variety of anomalies caused by threats or accidents.In this study, we proposed a detection system using microscopic to macroscopic designs for real-time anomaly detection.The key idea of the proposed system is that the system learns network traffic from multiple timelines rather than a single timeline of input data employed by most conventional detection systems.The advantages of the proposed system are 1) improving on detection performance over the single timeline, 2) flexibility in applying the proposed system to various types of networks or protocols, 3) robustness to incorrect training data or manipulating data by attackers, 4) performance improvement with weighted multiple timelines, and 5) real-time detectability for anomalies caused by threats or accidents.We also performed a series of experiments to examine the proposed system by employing three standard machine learning algorithms, namely multivariate normal distribution, k -nearest neighbor, and one-class support vector machine.In our experiments, we extracted nine key features on account of several selected attacks from a testbed data set.We examined capabilities of the proposed system in many aspects including detection performance, robustness, learning rate, i vi 8 Conclusion 116 vii 5.1 Examples of network traffic in our experiments, (top) normal traffic in training data, (bottom) Back attack in test data. . .viii 6.1 Detection performances of MND on different interval values by using individual features. . . . . . . . . . . . . . . . . . . .6.2 Detection performances of KNN on different interval values by using individual features. . . . . . . . . . . . . . . . . . . . . .6.3 Detection performances of SVM algorithm on different interval values by using individual features. . . . . . . . . . . . . . . .6.4 Average detection performances with different interval values using the MND, KNN, and OSVM. . . . . . . . . . . . . . . .6.5 Precision (P), Recall (R), and F-score (F) of MND using different features. . . . . . . . . . . . . . . . . . . . . . . . . . .6.6 Precision (P), Recall (R), and F-score (F) of KNN using different features. . . . . . . . . . . . . . . . . . . . . . . . . . .6.7 Precision (P), Recall (R), and F-score (F) of OSVM using different features. . . . . . . . . . .

Read the paper · More papers on PaperTik