Evaluation Framework for Netflow-based Network Anomaly Detection Systems using Synthetic Malicious Network Traffic
Shuvo Bardhan, Mitsuhiro Hatada · 2022 IEEE 46th Annual Computers, Software, and Applications Conference (COMPSAC) · 2022
In this paper, we present a procedure to evaluate netflow-based network anomaly detection (NF-NAD) systems based on accuracy of detection; and mean detection time. Conventionally, different variations of benign or normal traffic have been used to evaluate NF-NAD systems. Here we showcase a methodology where the benign traffic is constant through the entirety of the experiment. To evaluate NF-NAD systems, we create different variations of synthetic malicious network traffic, including not only traditional DDoS and scanning attacks but also a series of attacks by bot from infection to exfiltration. A two-phase approach is used to measure the accuracy and learning capability of the NF-NAD system. We have created a designed experiment (having factors, levels, and design points) to showcase our methodology.