Applying PCA for Traffic Anomaly Detection: Problems and Solutions - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2009

Applying PCA for Traffic Anomaly Detection: Problems and Solutions

Résumé

Spatial Principal Component Analysis (PCA) has been proposed for network-wide anomaly detection. A recent work has shown that PCA is very sensitive to calibration settings. Unfortunately, the authors did not provide further explanations for this observation. In this paper, we fill this gap and provide the reasoning behind the found discrepancies. We revisit PCA for anomaly detection and evaluate its performance on our data. We develop a slightly modified version of PCA that uses only data from a single router. Instead of correlating data across different spatial measurement points, we correlate the data across different metrics. With the help of the analyzed data, we explain the pitfalls of PCA and underline our argumentation with measurement results. We show that the main problem is that PCA fails to capture temporal correlation. We propose a solution to deal with this problem by replacing PCA with the Karhunen-Loeve transform. We find that when we consider temporal correlation, anomaly detection results are significantly improved.
Fichier principal
Vignette du fichier
infocom2009.pdf (125.57 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-00620090 , version 1 (07-09-2011)

Identifiants

Citer

Daniela Brauckhoff, Kavé Salamatian, Martin May. Applying PCA for Traffic Anomaly Detection: Problems and Solutions. Proceeding of IEEE INFOCOM 2009,, Apr 2009, Rio de Janeiro, Brazil. pp.2866-2870, ⟨10.1109/INFCOM.2009.5062248⟩. ⟨hal-00620090⟩
156 Consultations
2099 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More