TY - GEN
T1 - A study on detecting network anomalies using sampled flow statistics
AU - Kawahara, Ryoichi
AU - Mori, Tatsuya
AU - Kamiyama, Noriaki
AU - Harada, Shigeaki
AU - Asano, Shoichiro
PY - 2007
Y1 - 2007
N2 - We investigate how to detect network anomalies using flow statistics obtained through packet sampling. First, we show that network anomalies generating a huge number of small flows, such as network scans or SYN flooding, become difficult to detect when we execute packet sampling. This is because such flows are more unlikely to be sampled than normal flows. As a solution to this problem, we then show that spatially partitioning the monitored traffic into groups and analyzing the traffic of individual groups can increase the detectability of such anomalies: We also show the effectiveness of the partitioning method using network measurement data.
AB - We investigate how to detect network anomalies using flow statistics obtained through packet sampling. First, we show that network anomalies generating a huge number of small flows, such as network scans or SYN flooding, become difficult to detect when we execute packet sampling. This is because such flows are more unlikely to be sampled than normal flows. As a solution to this problem, we then show that spatially partitioning the monitored traffic into groups and analyzing the traffic of individual groups can increase the detectability of such anomalies: We also show the effectiveness of the partitioning method using network measurement data.
UR - http://www.scopus.com/inward/record.url?scp=46349085574&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=46349085574&partnerID=8YFLogxK
U2 - 10.1109/SAINT-W.2007.17
DO - 10.1109/SAINT-W.2007.17
M3 - Conference contribution
AN - SCOPUS:46349085574
SN - 0769527574
SN - 9780769527574
T3 - SAINT - 2007 International Symposium on Applications and the Internet - Workshops, SAINT-W
BT - 2007 International Symposium on Applications and the Internet - Workshops, SAINT-W
T2 - 2007 International Symposium on Applications and the Internet - Workshops, SAINT-W
Y2 - 15 January 2007 through 19 January 2007
ER -