Histogram-based network traffic representation for anomaly detection through PCA
Sara Baldoni, Federica Battisti · Computer Networks · 2025
The constant increase of the number of connected devices, as well as of their heterogeneity, has greatly expanded the security threat landscape. For this reason, the prompt and effective detection of network traffic anomalies has become critical. In this work, we propose a new network traffic representation that aims at providing a compact and constantly updated summary of the current network condition. In addition, we propose an anomaly detection method based on the Principal Component Analysis of the aforementioned network representation. The proposed method exploits one-second time windows of network traffic, thus allowing an immediate reaction to anomalies. It is completely unsupervised, thus enabling the detection of zero-day attacks, and it has a low computational complexity, thus reducing the required capabilities of the monitoring nodes. The performance analysis showed that the proposed approach achieves comparable results with respect to state-of-the-art methods. • A new traffic representation providing updated and compact summaries of the network. • An unsupervised, low-complexity, and prompt anomaly detector based on PCA. • An in-depth comparison between the proposed approach and state-of-the-art methods.