Comparative Studies Of Router-Based Observation Schemes For Anomaly Detection In Tcp/Udp Networks

Long Xu,Xinghuo Yu,Yong Feng,Fengling Han,Jiankun Hu,Zahir Tari
DOI: https://doi.org/10.1109/ICIT.2016.7475043
2016-01-01
Abstract:Anomaly detection in TCP/IP networks is very important to protect computer networks from cyber attacks. In recent years, several router-based observation schemes have been proposed for anomaly detection. Their effectiveness needs to be assessed. Furthermore, anomaly detection in TCP/UDP networks has not been fully explored using the observation schemes. In this paper, we conduct comparative studies using NS-2 to evaluate performances of four sliding mode based observation schemes, namely, sliding mode observer (SMO), terminal sliding mode observer (TSMO), super twisting observer (STO) and fast terminal sliding observer (FTSMO), for anomaly detection in TCP/UPD networks. It is shown that the FTSMO scheme performs best.
What problem does this paper attempt to address?