Degree-based Outlier Detection within IP Traffic Modelled as a Link Stream

06/06/2019
by   Audrey Wilmet, et al.
0

This paper aims at precisely detecting and identifying anomalous events in IP traffic. To this end, we adopt the link stream formalism which properly captures temporal and structural features of the data. Within this framework, we focus on finding anomalous behaviours with respect to the degree of IP addresses over time. Due to diversity in IP profiles, this feature is typically distributed heterogeneously, preventing us to directly find anomalies. To deal with this challenge, we design a method to detect outliers as well as precisely identify their cause in a sequence of similar heterogeneous distributions. We apply it to several MAWI captures of IP traffic and we show that it succeeds in detecting relevant patterns in terms of anomalous network activity.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/19/2021

Network Security Modeling using NetFlow Data: Detecting Botnet attacks in IP Traffic

Cybersecurity, security monitoring of malicious events in IP traffic, is...
research
04/24/2018

Anomaly Detection in Partially Observed Traffic Networks

This paper addresses the problem of detecting anomalous activity in traf...
research
05/03/2022

Deep Sequence Modeling for Anomalous ISP Traffic Prediction

Internet traffic in the real world is susceptible to various external an...
research
02/12/2023

On the Existence of Anomalies

The Independence Postulate (IP) is a finitary Church-Turing Thesis, sayi...
research
03/09/2023

On the Existence of Anomalies, The Reals Case

The Independence Postulate (IP) is a finitary Church-Turing Thesis, sayi...
research
06/28/2018

Detecting Port and Net Scan using Apache Spark

Today, due to the high number of attacks and of anomalous events in netw...

Please sign up or login with your details

Forgot password? Click here to reset