Network Anomaly Detection Using Time Series Analysis

QT Wu,ZQ Shao
DOI: https://doi.org/10.1109/icas-icns.2005.69
2005-01-01
Abstract:This paper presents a method of detecting network anomalies by analyzing the abrupt change of time series data obtained from management information base (MIB) variables. The method applies the auto-regressive (AR) process to model the abrupt change of time series data, and performs sequential hypothesis test to detect the anomalies. With time correlation and location correlation, the method determines not only the presence of anomalous activity, but also its occurring time and location. The experimental results show that the proposed method performs well in detecting the traffic-related anomalies
What problem does this paper attempt to address?