作者
Tarem Ahmed, Mark Coates, Anukool Lakhina
发表日期
2007/5/6
研讨会论文
IEEE INFOCOM 2007-26th IEEE International Conference on Computer Communications
页码范围
625-633
出版商
IEEE
简介
High-speed backbones are regularly affected by various kinds of network anomalies, ranging from malicious attacks to harmless large data transfers. Different types of anomalies affect the network in different ways, and it is difficult to know a priori how a potential anomaly will exhibit itself in traffic statistics. In this paper we describe an online, sequential, anomaly detection algorithm, that is suitable for use with multivariate data. The proposed algorithm is based on the kernel version of the recursive least squares algorithm. It assumes no model for network traffic or anomalies, and constructs and adapts a dictionary of features that approximately spans the subspace of normal behaviour. The algorithm raises an alarm immediately upon encountering a deviation from the norm. Through comparison with existing block-based offline methods based upon Principal Component Analysis, we demonstrate that our online …
引用总数
2007200820092010201120122013201420152016201720182019202020212022202320241851472218141513182019129631
学术搜索中的文章
T Ahmed, M Coates, A Lakhina - IEEE INFOCOM 2007-26th IEEE International …, 2007