Increasing Reliability in Network Traffic Anomaly Detection

Romain Fontugne · Institutional Repositories DataBase (IRDB) · 2011

Network traffic anomalies stand for a large fraction of the Internet traffic andcompromise the performance of the network resources. Detecting and diagnos-ing these threats is a laborious and time consuming task that network operatorsface daily. During the last decade researchers have concentrated their effortson this problem and proposed several tools to automate this task. Thereby,recent advances in anomaly detection have permitted to detect new or unknownanomalies by taking advantage of statistical analysis of the traffic. In spite ofthe advantages of these detection methods, researchers have reported severalcommon drawbacks discrediting their use in practice. Indeed, the challenge ofunderstanding the relation between the theory underlying these methods andthe actual Internet traffic raises several issues. For example, the difficulty ofselecting the optimal parameter set for these methods mitigates their perfor-mance and prevent network operators from using them. Moreover, due to thelack of ground truth data, approximate evaluations of these detection methodsprevent to provide accurate feedback on them and increase their reliability. Weaddress these issues, first, by proposing a pattern-recognition-based detectionmethod that overcomes the common drawbacks of anomaly detectors based onstatistical analysis, second, by providing both a benchmark tool that comparesthe results from diverse detectors and ground truth data obtained by combiningseveral anomaly detectors. The proposed pattern-recognition-based detector takes advantage of imageprocessing techniques to provide intuitive outputs and parameter set. An adap-tive mechanism automatically tuning its parameter set according to traffic fluc-tuations is also proposed. The resulting adaptive anomaly detector is easilyusable in practice, performs a high detection rate, and provides intuitive de-scription of the anomalies allowing to identify their root causes. A benchmark methodology is also developed in order to compare severaldetectors based on different theoretical background. This methodology allowsresearchers to accurately identify the differences between the results of diversedetectors. We employ this methodology along with an unsupervised combina-tion strategy to combine the output of four anomaly detectors. Thereby, thecombination strategy increases the overall reliability of the combined detectorsand it detects two times more anomalies than the best detector. We providethe results of this combination of detectors in the form of ground truth datacontaining various anomalies during 10 years of traffic.

Read the paper · More papers on PaperTik