SENATUS: An Approach to Joint Traffic Anomaly Detection and Root Cause Analysis

11/24/2017
by   Atef Abdelkefi, et al.
0

In this paper, we propose a novel approach, called SENATUS, for joint traffic anomaly detection and root-cause analysis. Inspired from the concept of a senate, the key idea of the proposed approach is divided into three stages: election, voting and decision. At the election stage, a small number of traffic flow sets (termed as senator flows)senator flows are chosen, which are used to represent approximately the total (usually huge) set of traffic flows. In the voting stage, anomaly detection is applied on the senator flows and the detected anomalies are correlated to identify the most possible anomalous time bins. Finally in the decision stage, a machine learning technique is applied to the senator flows of each anomalous time bin to find the root cause of the anomalies. We evaluate SENATUS using traffic traces collected from the Pan European network, GEANT, and compare against another approach which detects anomalies using lossless compression of traffic histograms. We show the effectiveness of SENATUS in diagnosing anomaly types: network scans and DoS/DDoS attacks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/14/2021

A Vision-based System for Traffic Anomaly Detection using Deep Learning and Decision Trees

Any intelligent traffic monitoring system must be able to detect anomali...
research
05/23/2019

Approximate String Matching for DNS Anomaly Detection

In this paper we propose a novel approach to identify anomalies in DNS t...
research
04/18/2018

NHAD: Neuro-Fuzzy Based Horizontal Anomaly Detection In Online Social Networks

Use of social network is the basic functionality of today's life. With t...
research
09/21/2017

AutoPerf: A Generalized Zero-Positive Learning System to Detect Software Performance Anomalies

In this paper, we present AutoPerf, a generalized software performance a...
research
02/11/2019

Scaling Up Anomaly Detection Using In-DRAM Working Set of Active Flows Table

In the zettabyte era, per-flow measurement becomes more challenging owin...
research
06/18/2023

Concept-Based Visual Analysis of Dynamic Textual Data

Analyzing how interrelated ideas flow within and between multiple social...
research
06/28/2018

Detecting Port and Net Scan using Apache Spark

Today, due to the high number of attacks and of anomalous events in netw...

Please sign up or login with your details

Forgot password? Click here to reset