Affiliation:
1. Institute of Telecommunications and Computer Science, Faculty of Telecommunications, Computer Science and Electrical Engineering, UTP University of Science and Technology, Al. S. Kaliskiego 7, 85-796 Bydgoszcz, Poland
Abstract
Abstract
In herein article an attempt of problem solution connected with anomaly detection in network traffic with the use of statistic models with long or short memory dependence was presented. In order to select the proper type of a model, the parameter describing memory on the basis of the Geweke and Porter-Hudak test was estimated. Bearing in mind that the value of statistic model depends directly on quality of data used for its creation, at the initial stage of the suggested method, outliers were identified and then removed. For the implementation of this task, the criterion using the value of interquartile range was used. The data prepared in this manner were useful for automatic creation of statistic models classes, such as ARFIMA and Holt-Winters. The procedure of calculation of model parameters’ optimal values was carried out as a compromise between the models coherence and the size of error estimation. Then, relations between the estimated network model and its actual parameters were used in order to detect anomalies in the network traffic. Considering the possibility of appearance of significant real traffic network fluctuations, procedure of updating statistic models was suggested. The results obtained in the course of performed experiments proved efficacy and efficiency of the presented solution.
Publisher
Oxford University Press (OUP)
Reference43 articles.
1. Anomaly detection in IP networks;Thottan;IEEE Transaction on Signal Processing, Special Issue of Signal Processing in Networking,2003
2. Characterization of network-wide anomalies in traffic flows;Lakhina,2004
3. Network anomaly detection system: the state of art of network behavior analysis. In Proceedings of the 2008 International Conference on Convergence and Hybrid Information;Lim;Technology,2008
Cited by
7 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献