4.7 Article

Network traffic analysis over clustering-based collective anomaly detection

期刊

COMPUTER NETWORKS
卷 205, 期 -, 页码 -

出版社

ELSEVIER
DOI: 10.1016/j.comnet.2022.108760

关键词

Anomaly detection; Network traffic analysis; Cluster analysis

资金

  1. National Key Research and Develop-ment Program of China [2020YFB2009500]

向作者/读者索取更多资源

In this paper, we propose a progressive exploration framework for collective anomaly detection on network traffic based on a clustering method called CCAD. Extensive experiments have shown its high detection rate.
Due to the ever-growing presence of network traffic, there has been a considerable amount of research on anomaly detection in network traffic by clustering. Most of them have not considered the problem that collective anomaly detection in network traffic. Collective anomaly might scatter among multiple clusters when applying the clustering-based algorithms in the anomaly detection. In this paper, we propose a progressive exploration framework for collective anomaly detection on network traffic based on a clustering method, called CCAD. CCAD enables analysts to effectively explore collective anomaly in network traffic. This framework is different from the other anomaly detection methods. It is based on the analysis of the influence of collective anomaly on the clustering results in the network traffic stream data. CCAD framework efficiently supports the collective anomaly exploration. As demonstrated by our extensive experiments with real-world data, CCAD has high detection rate in comparison with other existing methods.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据