Anomaly Clustering Based on Correspondence Analysis
Humayra Islam, Tarem Ahmed · 2018
Traffic patterns in backbone IP networks often deviate from the norm, to lead to events commonly termed as anomalies. Different algorithms have been proposed in literature to identify anomalies, but very few classifiers have been proposed to classify and group the signalled anomalies. Moreover, the classification algorithms typically have a predefined number of classes and use supervised learning methods. Some classifiers apply the windowing method to make the large amount of data scalable into small groups. This paper proposes a novel method of classification of anomalous data packets with unsupervised learning using the technique of Correspondence Analysis. Correspondence Analysis does not need a predefined number of clusters to begin the classification and can handle a large amount of data. We have applied our developed algorithm on real data from the US Abilene backbone network, and compared our results with existing clustering algorithms. The results indicate that our proposed algorithm yields the best results in terms of classifying anomalies amongst the most recent classification algorithms available.