TY - GEN
T1 - A method of detecting network anomalies in cyclic traffic
AU - Harada, Shigeaki
AU - Kawahara, Ryoichi
AU - Mori, Tatsuya
AU - Kamiyama, Noriaki
AU - Hasegawa, Haruhisa
AU - Yoshino, Hideaki
PY - 2008
Y1 - 2008
N2 - We present a method of detecting network anomalies, such as DDoS (distributed denial of service) attacks and flash crowds, automatically in real time. We evaluated this method using measured traffic data and found that it successfully differentiated suspicious traffic. In this paper, we focus on cyclic traffic, which has a daily and/or weekly cycle, and show that the differentiation accuracy is improved by utilizing such a cyclic tendency in anomaly detection. Our method differentiates suspicious traffic that has different statistical characteristics from normal traffic. At the same time, it learns about cyclic large- volume traffic, such as traffic for network operations, and finally considers it to be legitimate.
AB - We present a method of detecting network anomalies, such as DDoS (distributed denial of service) attacks and flash crowds, automatically in real time. We evaluated this method using measured traffic data and found that it successfully differentiated suspicious traffic. In this paper, we focus on cyclic traffic, which has a daily and/or weekly cycle, and show that the differentiation accuracy is improved by utilizing such a cyclic tendency in anomaly detection. Our method differentiates suspicious traffic that has different statistical characteristics from normal traffic. At the same time, it learns about cyclic large- volume traffic, such as traffic for network operations, and finally considers it to be legitimate.
UR - http://www.scopus.com/inward/record.url?scp=67249116117&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=67249116117&partnerID=8YFLogxK
U2 - 10.1109/GLOCOM.2008.ECP.396
DO - 10.1109/GLOCOM.2008.ECP.396
M3 - Conference contribution
AN - SCOPUS:67249116117
SN - 9781424423248
T3 - GLOBECOM - IEEE Global Telecommunications Conference
SP - 2057
EP - 2061
BT - 2008 IEEE Global Telecommunications Conference, GLOBECOM 2008
T2 - 2008 IEEE Global Telecommunications Conference, GLOBECOM 2008
Y2 - 30 November 2008 through 4 December 2008
ER -