Efficient Computer Network Anomaly Detection by Changepoint Detection Methods
arXiv:1212.1829 · doi:10.1109/JSTSP.2012.2233713
Abstract
We consider the problem of efficient on-line anomaly detection in computer network traffic. The problem is approached statistically, as that of sequential (quickest) changepoint detection. A multi-cyclic setting of quickest change detection is a natural fit for this problem. We propose a novel score-based multi-cyclic detection algorithm. The algorithm is based on the so-called Shiryaev-Roberts procedure. This procedure is as easy to employ in practice and as computationally inexpensive as the popular Cumulative Sum chart and the Exponentially Weighted Moving Average scheme. The likelihood ratio based Shiryaev-Roberts procedure has appealing optimality properties, particularly it is exactly optimal in a multi-cyclic setting geared to detect a change occurring at a far time horizon. It is therefore expected that an intrusion detection algorithm based on the Shiryaev-Roberts procedure will perform better than other detection schemes. This is confirmed experimentally for real traces. We also discuss the possibility of complementing our anomaly detection algorithm with a spectral-signature intrusion detection system with false alarm filtering and true attack confirmation capability, so as to obtain a synergistic system.
7 pages, 6 figures, to appear in "IEEE Journal of Selected Topics in Signal Processing"
Cited by in corpus (17)
- Real-Time Anomaly Detection for Streaming Analytics
- Automatic Inference of High-Level Network Intents by Mining Forwarding Patterns
- METER: A Dynamic Concept Adaptation Framework for Online Anomaly Detection
- Optimal Sequential Detection of Signals with Unknown Appearance and Disappearance Points in Time
- Quickest Change-Point Detection: A Bird's Eye View
- Fast Online Changepoint Detection via Functional Pruning CUSUM statistics
- Identification of malfunctioning quantum devices
- Identifying quantum change points for Hamiltonians
- Byzantine Fault Tolerant Distributed Quickest Change Detection
- fabisearch: A Package for Change Point Detection in and Visualization of the Network Structure of Multivariate High-Dimensional Time Series in R
- Penalty Learning for Optimal Partitioning using Multilayer Perceptron
- Sequential (Quickest) Change Detection: Classical Results and New Directions
- Online jump and kink detection in segmented linear regression: Statistical optimality meets computational efficiency
- Change Surfaces for Expressive Multidimensional Changepoints and Counterfactual Prediction
- Shedding Light on the Targeted Victim Profiles of Malicious Downloaders
- Real-Time Video Content Popularity Detection Based on Mean Change Point Analysis
- An Accurate Method for Determining the Pre-Change Run-Length Distribution of the Generalized Shiryaev--Roberts Detection Procedure