Intelligent flow-based sampling for effective network anomaly detection

G Androulidakis, S Papavassiliou - IEEE GLOBECOM 2007 …, 2007 - ieeexplore.ieee.org
IEEE GLOBECOM 2007-IEEE Global Telecommunications Conference, 2007ieeexplore.ieee.org
Sampling has become an essential component of scalable Internet traffic monitoring and
anomaly detection. In this paper, the emphasis is placed on the evaluation of the impact of
using intelligent flow sampling techniques on the anomaly detection process. Based on the
observation that small flows are usually the source of many network attacks (DDoS,
portscans, worm propagation) we first introduce a new flow sampling methodology that
focuses on the selection of small flows and achieves to improve anomaly detection …
Sampling has become an essential component of scalable Internet traffic monitoring and anomaly detection. In this paper, the emphasis is placed on the evaluation of the impact of using intelligent flow sampling techniques on the anomaly detection process. Based on the observation that small flows are usually the source of many network attacks (DDoS, portscans, worm propagation) we first introduce a new flow sampling methodology that focuses on the selection of small flows and achieves to improve anomaly detection effectiveness, while at the same time reduces the number of selected flows. The performance evaluation of the impact of intelligent flow-based sampling on the anomaly detection process is achieved through the adoption and application of a sequential non-parametric Change-Point Detection anomaly detection method on realistic data that have been collected from a real operational university campus network.
ieeexplore.ieee.org
以上显示的是最相近的搜索结果。 查看全部搜索结果