Skip to Main content Skip to Navigation
Journal articles

A novel approach for anomaly detection over high-speed networks

Abstract : This paper provides a new framework for efficient detection and identification of network anomalies over high speed links, in early stage of its occurrence to quickly react by taking the appropriate countermeasures. The proposed framework is based on change point detection in counters value of reversible sketch, which aggregates multiple data streams from high speed links in a stretched database. To detect network anomalies, we apply the cumulative sum (CUSUM) algorithm at the counter value of each bucket in the proposed reversible sketch, to detect change point occurrence and to uncover culprit flows via a new approach for sketch inversion. Theoretical framework for attacks detection is presented. We also give the results of our experiments analysis over two real data traces containing anomalies, and extensively analyzed in OSCAR French research project. Our analysis results from real-time internet traffic and online implementation over Endace DAG 3.6ET card show that our proposed architecture is able to detect culprit flows quickly with a high level of accuracy.
Document type :
Journal articles
Complete list of metadata
Contributor : Bibliothèque Télécom Bretagne <>
Submitted on : Tuesday, September 10, 2019 - 12:30:28 AM
Last modification on : Saturday, May 1, 2021 - 3:54:38 AM

Links full text



Osman Salem, Sandrine Vaton, Annie Gravey. A novel approach for anomaly detection over high-speed networks. Lecture notes in electrical engineering, 2009, 30, pp.49 - 68. ⟨10.1007/978-0-387-85555-4_4⟩. ⟨hal-02282371⟩



Record views