Distributed detection/localization of change-points in high-dimensional network traffic data - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Statistics and Computing Année : 2011

Distributed detection/localization of change-points in high-dimensional network traffic data

Résumé

We propose a novel approach for distributed statistical detection of change-points in high-volume network traffic. We consider more specifically the task of detecting and identifying the targets of Distributed Denial of Service (DDoS) attacks. The proposed algorithm, called DTopRank, performs distributed network anomaly detection by aggregating the partial information gathered in a set of network monitors. In order to address massive data while limiting the communication overhead within the network, the approach combines record filtering at the monitor level and a nonparametric rank test for doubly censored time series at the central decision site. The performance of the DTopRank algorithm is illustrated both on synthetic data as well as from a traffic trace provided by a major Internet service provider.
Fichier principal
Vignette du fichier
version_hal.pdf (820.86 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00420862 , version 1 (29-09-2009)
hal-00420862 , version 2 (20-09-2011)

Identifiants

Citer

Alexandre Lung-Yut-Fong, Céline Lévy-Leduc, Olivier Cappé. Distributed detection/localization of change-points in high-dimensional network traffic data. Statistics and Computing, 2011, pp.1-12. ⟨10.1007/s11222-011-9240-5⟩. ⟨hal-00420862v2⟩
137 Consultations
138 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More