Visible to the public Biblio

Filters: Author is Ardon, S.  [Clear All Filters]
2015-05-05
Babaie, T., Chawla, S., Ardon, S., Yue Yu.  2014.  A unified approach to network anomaly detection. Big Data (Big Data), 2014 IEEE International Conference on. :650-655.

This paper presents a unified approach for the detection of network anomalies. Current state of the art methods are often able to detect one class of anomalies at the cost of others. Our approach is based on using a Linear Dynamical System (LDS) to model network traffic. An LDS is equivalent to Hidden Markov Model (HMM) for continuous-valued data and can be computed using incremental methods to manage high-throughput (volume) and velocity that characterizes Big Data. Detailed experiments on synthetic and real network traces shows a significant improvement in detection capability over competing approaches. In the process we also address the issue of robustness of network anomaly detection systems in a principled fashion.