Title
Detecting traffic anomalies using an equilibrium property
Abstract
When many flows are multiplexed on a non-saturated link, their volume changes over short timescales tend to cancel each other out, making the average change across flows close to zero. This equilibrium property holds if the flows are nearly independent, and it is violated by traffic changes caused by several correlated flows. We exploit this empirical property to design a computationally simple anomaly detection method.
Year
DOI
Venue
2010
10.1145/1811039.1811095
Proceedings of the ACM SIGMETRICS international conference on Measurement and modeling of computer systems
Keywords
Field
DocType
anomaly detection,statistical test
Anomaly detection,Computer science,Simulation,Algorithm,Real-time computing,Exploit,Multiplexing,Statistical hypothesis testing
Conference
Volume
Issue
ISSN
38
1
0163-5999
Citations 
PageRank 
References 
1
0.35
2
Authors
4
Name
Order
Citations
PageRank
Fernando Silveira1412.23
Christophe Diot27831590.69
Nina Taft32109154.92
ramesh govindan4154302144.86