Network Anomaly Detection Based on Frequent Sub-Graph Mining Approach and Association Analysis

Fangyuan Cheng,Xiaofeng Qiu
DOI: https://doi.org/10.1109/icnidc.2016.7974527
2016-01-01
Abstract:In this paper, an anomaly detection method based on frequent sub-graph mining and association analysis is introduced to ensure the security of the SDN. With this method, the network behavior data in SDN are represented as a graph, abnormal sub-graphs of which are readily detectable. And patterns of the detected abnormal behaviors are able to be identified. Furthermore, an ensemble method based on Bagging algorithm is proposed to improve the detection accuracy. Experiment with global flow table data based on SDN indicated that this approach was capable of detecting anomalies in SDN. Moreover, to illustrate the effectiveness of this method in other aspects, comparisons with KDD99 data set were conducted. And the results verified its excellent ability in reducing false alarms and the effect of the ensemble method on improving the detection accuracy.
What problem does this paper attempt to address?