IJNM - Network Anomaly Detection Using a Cross-Correlation Based LRD Analysis Camera Ready.pdf (6.14 MB)
Network anomaly detection using a cross‐correlation‐based long‐range dependence analysis
journal contribution
posted on 2020-06-24, 13:10 authored by Basil AsSadhan, Abraham Alzoghaiby, Hamad Binsalleeh, Kostas KyriakopoulosKostas Kyriakopoulos, Sangarapillai LambotharanSangarapillai LambotharanThe detection of anomalies in network traffic is an important task in today’s Internet. Among various anomaly detection methods, the techniques based on examination of the long-range dependence (LRD) behavior of network traffic stands out to be powerful. In this paper, we reveal anomalies in aggregated network traffic by examining the LRD behavior based on the cross-correlation function of the bidirectional control and data planes traffic. Specifically, observing that the conventional cross-correlation function has a low measure of dissimilarity between the two planes, which leads to a reduced anomaly detection performance, we propose a modification of the cross-correlation function to mitigate this issue. The performance of the proposed method is analyzed using a relatively recent Internet traffic captured at King Saud University. The results demonstrate that using the modified cross-correlation function has the ability to detect low volume and short duration attacks. It also compensates for some misdetections exhibited by using the autocorrelation structures of the bidirectional traffic of the control, data, and WHOLE (combined control and data) planes traffic.
Funding
Gulf Science, Innovation, and Knowledge Economy Programme of the U.K. Government under UK-Gulf Institutional Link Grant IL 279339985.
Research Center at the College of Engineering, King Saud University.
History
School
- Mechanical, Electrical and Manufacturing Engineering
Published in
International Journal of Network ManagementVolume
30Issue
6Publisher
WileyVersion
- AM (Accepted Manuscript)
Rights holder
© John Wiley & Sons, LtdPublisher statement
This is the peer reviewed version of the following article: ASSADHAN, B. … et al, 2020. Network anomaly detection using a cross‐correlation‐based long‐range dependence analysis. International Journal of Network Management, 30 (6), e2129, which has been published in final form at https://doi.org/10.1002/nem.2129. This article may be used for non-commercial purposes in accordance with Wiley Terms and Conditions for Use of Self-Archived Versions.Acceptance date
2020-06-10Publication date
2020-07-30Copyright date
2020ISSN
1055-7148eISSN
1099-1190Publisher version
Language
- en