SVC-Based Multivariate Control Charts for Automatic Anomaly Detection in Computer Networks

Zhisheng Zhang,Xuejun Zhu,Jionghua Jin
DOI: https://doi.org/10.1109/CONIELECOMP.2007.99
2007-01-01
Abstract:The design of multivariate control charts for automatic anomaly detection in computer networks is a challenging research issue due to the complexity of the data structure of the network operational data. In general, the design of statistical multivariate control charts is limited to a Gaussian distribution assumption or a pre-known probability distribution model, which is hardly applicable to the computer operation data. The paper is motivated by this timely need to develop SVC (support vector clustering) based multivariate control charts, which do not require the data to have a pre-known probability distribution model. The proposed method is validated through the simulations by comparing with the popularly used statistical T2 multivariate control charts. The effectiveness of the method is also demonstrated through automatic anomaly detection of typical computer intrusions.
What problem does this paper attempt to address?