TY - GEN
T1 - Detection accuracy of network anomalies using sampled flow statistics
AU - Kawahara, Ryoichi
AU - Ishibashi, Keisuke
AU - Mori, Tatsuya
AU - Kamiyama, Noriaki
AU - Harada, Shigeaki
AU - Asano, Shoichiro
PY - 2007
Y1 - 2007
N2 - We investigate the detection accuracy of network anomalies when we use flow statistics obtained through packet sampling. We have already shown, through a case study based on measurement data, that network anomalies generating a huge number of small flows, such as network scans or SYN flooding, become hard to detect when we perform packet sampling. In this paper, we first develop an analytical model that enables us to quantitatively evaluate the effect of packet sampling on the detection accuracy and then investigate why detection accuracy worsens when the packet sampling rate decreases. In addition, we show that, even with a low sampling rate, spatially partitioning the monitored traffic into groups makes it possible to increase the detection accuracy. We also develop a method of determining an appropriate number of partitioned groups and show its effectiveness.
AB - We investigate the detection accuracy of network anomalies when we use flow statistics obtained through packet sampling. We have already shown, through a case study based on measurement data, that network anomalies generating a huge number of small flows, such as network scans or SYN flooding, become hard to detect when we perform packet sampling. In this paper, we first develop an analytical model that enables us to quantitatively evaluate the effect of packet sampling on the detection accuracy and then investigate why detection accuracy worsens when the packet sampling rate decreases. In addition, we show that, even with a low sampling rate, spatially partitioning the monitored traffic into groups makes it possible to increase the detection accuracy. We also develop a method of determining an appropriate number of partitioned groups and show its effectiveness.
UR - http://www.scopus.com/inward/record.url?scp=39349105464&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=39349105464&partnerID=8YFLogxK
U2 - 10.1109/GLOCOM.2007.376
DO - 10.1109/GLOCOM.2007.376
M3 - Conference contribution
AN - SCOPUS:39349105464
SN - 1424410436
SN - 9781424410439
T3 - GLOBECOM - IEEE Global Telecommunications Conference
SP - 1959
EP - 1964
BT - IEEE GLOBECOM 2007 - 2007 IEEE Global Telecommunications Conference, Proceedings
T2 - 50th Annual IEEE Global Telecommunications Conference, GLOBECOM 2007
Y2 - 26 November 2007 through 30 November 2007
ER -