A novel approach for anomaly detection over high-speed networks - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Lecture notes in electrical engineering Année : 2009

A novel approach for anomaly detection over high-speed networks

Osman Salem
  • Fonction : Auteur
  • PersonId : 1027543
Sandrine Vaton
Annie Gravey

Résumé

This paper provides a new framework for efficient detection and identification of network anomalies over high speed links, in early stage of its occurrence to quickly react by taking the appropriate countermeasures. The proposed framework is based on change point detection in counters value of reversible sketch, which aggregates multiple data streams from high speed links in a stretched database. To detect network anomalies, we apply the cumulative sum (CUSUM) algorithm at the counter value of each bucket in the proposed reversible sketch, to detect change point occurrence and to uncover culprit flows via a new approach for sketch inversion. Theoretical framework for attacks detection is presented. We also give the results of our experiments analysis over two real data traces containing anomalies, and extensively analyzed in OSCAR French research project. Our analysis results from real-time internet traffic and online implementation over Endace DAG 3.6ET card show that our proposed architecture is able to detect culprit flows quickly with a high level of accuracy.

Dates et versions

hal-02282371 , version 1 (10-09-2019)

Identifiants

Citer

Osman Salem, Sandrine Vaton, Annie Gravey. A novel approach for anomaly detection over high-speed networks. Lecture notes in electrical engineering, 2009, 30, pp.49 - 68. ⟨10.1007/978-0-387-85555-4_4⟩. ⟨hal-02282371⟩
21 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More