Title
A unified approach to network anomaly detection
Abstract
This paper presents a unified approach for the detection of network anomalies. Current state of the art methods are often able to detect one class of anomalies at the cost of others. Our approach is based on using a Linear Dynamical System (LDS) to model network traffic. An LDS is equivalent to Hidden Markov Model (HMM) for continuous-valued data and can be computed using incremental methods to manage high-throughput (volume) and velocity that characterizes Big Data. Detailed experiments on synthetic and real network traces shows a significant improvement in detection capability over competing approaches. In the process we also address the issue of robustness of network anomaly detection systems in a principled fashion.
Year
DOI
Venue
2014
10.1109/BigData.2014.7004288
BigData Conference
Keywords
Field
DocType
Big Data,computer network security,hidden Markov models,Big Data,HMM,LDS,continuous-valued data,hidden Markov model,linear dynamical system,network anomaly detection,network traffic
Data mining,Linear dynamical system,Anomaly detection,Computer science,Incremental methods,Network simulation,Robustness (computer science),Artificial intelligence,Hidden Markov model,Big data,Machine learning
Conference
ISSN
Citations 
PageRank 
2639-1589
1
0.37
References 
Authors
9
4
Name
Order
Citations
PageRank
Tahereh Babaie110.37
Sanjay Chawla21372105.09
Sebastien Ardon326017.24
Yue Yu410.37