An Intelligent and Time-Efficient DDoS Identification Framework for Real-Time Enterprise Networks SAD-F: Spark Based Anomaly Detection Framework

01/21/2020
by   Awais Ahmed, et al.
0

Anomaly detection is a crucial step for preventing malicious activities in the network and keeping resources available all the time for legitimate users. It is noticed from various studies that classical anomaly detectors work well with small and sampled data, but the chances of failures increase with real-time (non-sampled data) traffic data. In this paper, we will be exploring security analytic techniques for DDoS anomaly detection using different machine learning techniques. In this paper, we are proposing a novel approach which deals with real traffic as input to the system. Further, we study and compare the performance factor of our proposed framework on three different testbeds including normal commodity hardware, low-end system, and high-end system. Hardware details of testbeds are discussed in the respective section. Further in this paper, we investigate the performance of the classifiers in (near) real-time detection of anomalies attacks. This study also focused on the feature selection process that is as important for the anomaly detection process as it is for general modeling problems. Several techniques have been studied for feature selection and it is observed that proper feature selection can increase performance in terms of model's execution time - which totally depends upon the traffic file or traffic capturing process.

READ FULL TEXT
research
01/21/2020

Live Anomaly Detection based on Machine Learning Techniques SAD-F: Spark Based Anomaly Detection Framework

Anomaly detection is a crucial step for preventing malicious activities ...
research
03/17/2014

Multi-task Feature Selection based Anomaly Detection

Network anomaly detection is still a vibrant research area. As the fast ...
research
12/12/2018

Real-Time Anomaly Detection With HMOF Feature

Anomaly detection is a challenging problem in intelligent video surveill...
research
12/05/2022

FEMa-FS: Finite Element Machines for Feature Selection

Identifying anomalies has become one of the primary strategies towards s...
research
05/14/2019

Network Attacks Anomaly Detection Using SNMP MIB Interface Parameters

Many approaches have evolved to enhance network attacks detection anomal...
research
07/03/2014

Anomaly Detection Based on Aggregation of Indicators

Automatic anomaly detection is a major issue in various areas. Beyond me...
research
06/28/2018

Detecting Port and Net Scan using Apache Spark

Today, due to the high number of attacks and of anomalous events in netw...

Please sign up or login with your details

Forgot password? Click here to reset