Towards Online Anomaly Detection by Combining Multiple Detection Methods and Storm

Ziyu Wang,Jiahai Yang,Hui Zhang,Chenxi Li,Shize Zhang,Hui Wang
DOI: https://doi.org/10.1109/noms.2016.7502903
2016-01-01
Abstract:In this paper, we illustrate the significance and advantage of combining the results of multiple detection methods. We implement these methods as bolts in a Apache Storm cluster which is a famous real-time computation framework. We simulate two kinds of anomalies — one involving large number of small network flows and the other involving small number of large network flows. The experiments show that combining multiple methods outperforms any single detection method from the point of view of statistics. Besides, we observe that all the results are outputted in real time without delay, which means that our detection platform is indeed an effective online system.
What problem does this paper attempt to address?