Related Experiment Videos
Statistical analysis of network traffic for adaptive faults detection
1IBM Business Consulting, 2-4-1 Marunochi Chiyoda-ku, Tokyo, Japan. hajji@jp.ibm.com
IEEE Transactions on Neural Networks
|October 29, 2005
Summary
This study introduces a novel method for network anomaly detection by establishing a baseline of normal network operations. The approach effectively identifies unusual traffic patterns and adapts to daily changes, ensuring low false alarm rates.
Area of Science:
- Computer Science
- Network Engineering
- Data Science
Background:
- Network anomalies pose significant challenges to system stability and security.
- Accurate baselining of normal network operation is crucial for effective anomaly detection.
- Existing methods may struggle with dynamic traffic patterns and high fluctuation rates.
Purpose of the Study:
- To develop a robust method for establishing normal operation baselines in network traffic.
- To enable automatic detection of network anomalies using the derived baseline.
- To adapt to diurnal traffic patterns and maintain a low false alarm rate.
Main Methods:
- Modeling network traffic as a finite mixture model.
- Utilizing stochastic approximation of the maximum likelihood function for parameter estimation.
- Employing an online change point detection framework for real-time anomaly identification.
Main Results:
- The proposed baseline random variable is stationary with a mean of zero under normal operation.
- Anomalous events are detected as abrupt jumps in the baseline mean.
- Experimental results demonstrate effective detection of unusual traffic changes and adaptation to diurnal patterns.
Conclusions:
- The developed monitoring agent successfully detects network anomalies with a low false alarm rate.
- Tailoring traffic modeling to specific goals, like anomaly detection, is efficient and achievable.
- The method provides an analytical expression for false alarm rate, enabling automatic threshold selection.