Volume anomaly detection in data networks : an optimal detection algorithm vs the PCA approach - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2009

Volume anomaly detection in data networks : an optimal detection algorithm vs the PCA approach

Résumé

The crucial future role of Internet in society makes of network monitoring a critical issue for network operators in future network scenarios. The Future Internet will have to cope with new and different anomalies, motivating the development of accurate detection algorithms. This paper presents a novel approach to detect unexpected and large traffic variations in data networks. We introduce an optimal volume anomaly detection algorithm in which the anomaly-free traffic is treated as a nuisance parameter. The algorithm relies on an original parsimonious model for traffic demands which allows detecting anomalies from link traffic measurements, reducing the overhead of data collection. The performance of the method is compared to that obtained with the Principal Components Analysis (PCA) approach. We choose this method as benchmark given its relevance in the anomaly detection literature. Our proposal is validated using data from an operational network, showing how the method outperforms the PCA approach.

Dates et versions

hal-00486765 , version 2 (26-05-2010)
hal-00486765 , version 1 (20-07-2010)

Identifiants

Citer

Pedro Casas Hernandez, Lionel Fillatre, Sandrine Vaton, Igor V. Nikiforov. Volume anomaly detection in data networks : an optimal detection algorithm vs the PCA approach. FITraMEn 2008, 2008, Porto, Portugal. pp.113, ⟨10.1007/978-3-642-04576-9⟩. ⟨hal-00486765v2⟩
108 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More