Optimal volume anomaly detection in network traffic flows - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2008

Optimal volume anomaly detection in network traffic flows

Résumé

Optimal detection of unusual and significant changes in network Origin-Destination (OD) traffic volumes from simple link load measurements is considered in the paper. The ambient traffic, i.e. the OD traffic matrix corresponding to the non-anomalous network state, is unknown and it is considered here as a nuisance parameter because it can mask the anomalies. Since the OD traffic matrix is not recoverable from simple link load measurements, the anomaly detection is an ill-posed decision-making problem. The method proposed in this paper consists of finding a linear parsimonious model of ambient traffic (nuisance parameter) and detecting anomalies by using an invariant detection algorithm based on a separation of the measurement space into disjoint subspaces corresponding to normal and anomalous network traffic. The method’s ability to detect anomalies is evaluated in real traffic from Abilene, a United States backbone network. The theoretically expected results are confirmed.
Fichier principal
Vignette du fichier
Eusipco2008_VersionFinale.pdf (115.38 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00540901 , version 1 (29-11-2010)

Identifiants

  • HAL Id : hal-00540901 , version 1

Citer

Lionel Fillatre, Igor V. Nikiforov, Pedro Casas Hernandez, Sandrine Vaton. Optimal volume anomaly detection in network traffic flows. EUSIPCO'08 : 16th European Signal Processing Conference, Aug 2008, Lausanne, Switzerland. ⟨hal-00540901⟩
122 Consultations
192 Téléchargements

Partager

Gmail Facebook X LinkedIn More