Towards Detecting Traffic Changes in Real-World Heterogeneous Multi-Cloud Environments
Marleen Sichermann, Katharina Dietz, Leticia Serejo Kunz, Jochen Kögel, Stefan Cieiβler, Tobias Hoβfeld · 2025
The growing complexity and dynamism of modern networks make change and anomaly detection a challenging problem, especially in large-scale environments with non-stationary traffic. Many existing methods rely on high-resolution packet-level data, limiting their use in real-world deployments that primarily generate aggregated data like NetFlow records. To address this, we introduce a scalable, lightweight approach for detecting behavioral shifts in network traffic using NetFlow-based monitoring data. Our method integrates principal component analysis (PCA) for dimensionality reduction, time series decomposition to isolate trends, and the Pruned Exact Linear Time (PELT) algorithm for detecting mean shifts. We evaluate its effectiveness in a large-scale nationwide enterprise network in Germany, demonstrating its ability to identify change points in traffic. Additionally, we assess the expressiveness of various features in detecting these shifts.