Novel Traffic Sampling Method for Anomaly Detection

PAN Qiao,PEI Changxing,ZHU Changhua
DOI: https://doi.org/10.3321/j.issn:0253-987x.2008.02.011
2008-01-01
Abstract:In order to reduce the impact of sampled traffic on network anomaly detecting,a novel method with variable sampling rates in traffic sampling is proposed.By using the hash pattern matching algorithm,the incoming packets are classified by flow's ID and the packet's positions in the flow are recorded.Then,various sampling rates are specified according to the decreasing order function of the flow that the incoming packet belongs to.Experiment results show that the method increases the sampling rates to small flows,and resolves the problem that a great many network anomalies are discarded by the random packet sampling that has a bias towards large flows,and that the accuracy of anomaly detecting is improved.
What problem does this paper attempt to address?