Effectiveness Assessment of Time Series Models for Anomalies Detection in Real Network Traffic
Delia Hulskamp, Cristian Cappo · 2022
In the field of Information Technology, threats have evolved and diversified. For this reason, detecting and identifying these threats is essential to prevent abnormal behavior within networks. Using Network Intrusion Detection Systems (NIDS) to analyze network traffic behavior helps identify and prevent malicious activities. This work assesses the effectiveness of three Time Series models for anomaly detection: ARIMA, Holt- Winters, and Moving Averages, implemented in Snort, a popular NIDS, using a public dataset with real network traffic collected in a Spanish ISP with long-term data traffic. The evaluated models have detected between 99% and 100% of DoS, PortScanning, and UDPScan attacks included in the dataset with low false alarms.