Detecting anomalies from big network traffic data using an adaptive detection approach
Article
Article Title | Detecting anomalies from big network traffic data using an adaptive detection approach |
---|---|
ERA Journal ID | 17908 |
Article Category | Article |
Authors | Zhang, Ji (Author), Li, Hongzhou (Author), Gao, Qigang (Author), Wang, Hai (Author) and Luo, Yonglong (Author) |
Journal Title | Information Sciences |
Journal Citation | 318, pp. 91-110 |
Number of Pages | 20 |
Year | 2015 |
Publisher | Elsevier |
Place of Publication | Philadelphia, PA. United States |
ISSN | 0020-0255 |
1872-6291 | |
Digital Object Identifier (DOI) | https://doi.org/10.1016/j.ins.2014.07.044 |
Abstract | The unprecedented explosion of real-life big data sets have sparked a lot of research interests in data mining in recent years. Many of these big data sets are generated in network environment and are characterized by a dauntingly large size and high dimensionality which pose great challenges for detecting useful knowledge and patterns, such as network traffic anomalies, from them. In this paper, we study the problem of anomaly detection in big network connection data sets and propose an outlier detection technique, called Adaptive Stream Projected Outlier deTector (A-SPOT), to detect anomalies from large data sets using a novel adaptive subspace analysis approach. A case study of A-SPOT is conducted in this paper by deploying it to the 1999 KDD CUP anomaly detection application. Innovative approaches for training data generation, anomaly classification and false positive reduction are proposed in this paper as well to better tailor A-SPOT to deal with the case study. Experimental results demonstrate that A-SPOT is effective and efficient in detecting anomalies from network data sets and outperforms existing detection methods. |
Keywords | anomaly detection; big data; outlier detection |
ANZSRC Field of Research 2020 | 469999. Other information and computing sciences not elsewhere classified |
400607. Signal processing | |
461301. Coding, information theory and compression | |
Public Notes | Files associated with this item cannot be displayed due to copyright restrictions. |
Byline Affiliations | School of Agricultural, Computational and Environmental Sciences |
Guilin University of Electronic Technology, China | |
Dalhousie University, Canada | |
Saint Mary's University, Canada | |
Anhui Normal University, China | |
Institution of Origin | University of Southern Queensland |
https://research.usq.edu.au/item/q2x64/detecting-anomalies-from-big-network-traffic-data-using-an-adaptive-detection-approach
1822
total views6
total downloads2
views this month0
downloads this month