Traffic Model Analysis for Anomaly Detection

Zonglin Li,Guangmin Hu,Ruqiang Zhou
DOI: https://doi.org/10.1142/9789812799524_0363
2008-01-01
Abstract:Traffic modeling as one of the ways to describe the normal behavior of network traffic is used to detect anomaly. Due to the self-similar model and multi-fractal model are inherently unable to capture the nature of traffic data in all time scales, we propose a novel anomaly detection method based on IDC model analysis to describe the characteristic of traffic data more accurately. By studying the influences of anomalous traffic on the estimation of IDC model through wavelet transform modulus maxima, a cumulative deviation is defined to estimate abnormal behavior. The simulation results show that our method is more sensitive to small anomalous traffic than detection methods based on H parameter analysis, and can accurately detect the anomalies which would not cause the Hurst parameter change evidently. Therefore, it is suite for the early stage detection of anomaly traffic.
What problem does this paper attempt to address?