Improving Network Traffic Anomaly Detection for Cloud Computing Services
Publikation: Beitrag zu Konferenzen › Paper › Beigetragen › Begutachtung
Beitragende
Abstract
Efficient network traffic anomaly detection is a widely studied problem on avoiding attacks and unwanted use of communication infrastructures. Existing techniques to detect, prevent or monitor these attacks are usually based on known thresholds, on the construction of profiles of normal traffic patterns, or on signature pattern matching of anomalous behavior (i.e., viruses and attacks). On the other hand, there are dynamic techniques that strive to predict the system's clutter degree; i.e., the system entropy, supposing that outliers translate to anomalies. We have developed and analyzed the accuracy of a network anomaly detector for Cloud Computing Systems based on the entropy of network traffic metrics. Although entropy-based solutions do not suppose hard knowledge of the system, the results point out to the need for more accurate adjustment of system parameters, taking into consideration the nature of the data, frequency of events, and the variation of metric values. To improve the results, unsupervised machine learning algorithms were added to the anomaly detection process.
Details
Originalsprache | Englisch |
---|---|
Seiten | 107 to 113 |
Publikationsstatus | Veröffentlicht - 2014 |
Peer-Review-Status | Ja |
Konferenz
Titel | Ninth International Conference on Systems and Networks Communications |
---|---|
Kurztitel | INSNC 2014 |
Veranstaltungsnummer | 9 |
Dauer | 12 - 16 Oktober 2014 |
Bekanntheitsgrad | Internationale Veranstaltung |
Stadt | Nice |
Land | Frankreich |
Schlagworte
Forschungsprofillinien der TU Dresden
DFG-Fachsystematik nach Fachkollegium
Schlagwörter
- Network traffic anomaly detection, Cloud Computing, Machine learning, entropy, Entropy