Analyzing and Visualizing Anomalies and Events in Time Series of Network Traffic

Qinpei Zhao,Yinjia Zhang,Yang Shi,Jiangfeng Li
DOI: https://doi.org/10.1007/978-3-030-19861-9_2
2019-01-01
Abstract:The traffic among the hosts and behaviors of the anomalous hosts in the network is usually complex. In network traffic, there is a key problem that is how to identify the security incidents. The corresponding question that who have contributed to the incidents is arisen then. A method, which detects both anomalies and events at the same time is quite helpful. A data from network traffic can be composed of the hosts and different attributes (traffic flow like amount of upload package and download package) in time series. Based on the structure of the network traffic data, we propose an anomaly and event detection method based on the network attributes in time series. The method analyzes both the host’s behavior and the temporal features of the network traffic.
What problem does this paper attempt to address?