PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 25, 2006230 citations

Detection and identification of network anomalies using sketch subspaces

View Full Paper
XLXin LiFBFang BianMCMark Crovella

Key Points

Key points are not available for this paper at this time.

Abstract

Network anomaly detection using dimensionality reduction techniques has received much recent attention in the literature. For example, previous work has aggregated netflow records into origin-destination (OD) flows, yielding a much smaller set of dimensions which can then be mined to uncover anomalies. However, this approach can only identify which OD flow is anomalous, not the particular IP flow(s) responsible for the anomaly. In this paper we show how one can use random aggregations of IP flows (i.e., sketches) to enable more precise identification of the underlying causes of anomalies. We show how to combine traffic sketches with a subspace method to (1) detect anomalies with high accuracy and (2) identify the IP flows(s) that are responsible for the anomaly. Our method has detection rates comparable to previous methods and detects many more anomalies than prior work, taking us a step closer towards a robust on-line system for anomaly detection and identification.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Li et al. (2006) studied this question.

synapsesocial.com/papers/69d952b000ab073a27836113https://doi.org/10.1145/1177080.1177099
Ask AI
Helpful
Bookmark
Share
View Full Paper