跳到主要导航 跳到搜索 跳到主要内容

Towards a multi-layers anomaly detection framework for analyzing network traffic

  • Bo Li
  • , Simin Zhang
  • , Ke Li*
  • *此作品的通讯作者
  • Beihang University
  • Guangxi Key Lab of Multi-source Information Mining & Security

科研成果: 期刊稿件文章同行评审

摘要

Anomaly detection plays a crucial part in identifying unforeseen attacks for network and information security. However, the accuracy of existing network anomaly detection approaches is limited because of the lack of sufficient and high-quality features. Most research works only take information from one network layer into account, which leads to a situation that some key features of other network layers are omitted. To address this issue, we propose a novel approach, named Multi-Layers Anomaly Detection, which extracts and combines features from different network layers. In order to reduce redundancy and noise derived from the combination of multiple layers, an algorithm called RanPF is designed by applying principal components analysis (PCA) into random forest (RF) algorithm. RanPF uses features selected by PCA to decide the height of every tree in RF and provides a method to select which features for tree nodes to use according to the weights of principal components. To obtain high-quality features, we adopt an attribute learning mechanism. Naive Bayes is used to characterize the attribute information, which is fast and simple compared with other learning algorithms such as SVM. In addition, a series of experiments conducted on two real-life datasets demonstrate that our approach outperforms the state-of-the-art methods in terms of detection rate and false alarm rate. MLAD achieves about 99% detection rate and about 0.6% false alarm rate on average when the ratio of the training set is 60%.

源语言英语
文章编号e3955
期刊Concurrency and Computation: Practice and Experience
29
14
DOI
出版状态已出版 - 25 7月 2017

学术指纹

探究 'Towards a multi-layers anomaly detection framework for analyzing network traffic' 的科研主题。它们共同构成独一无二的学术指纹。

引用此