CNRS-Wide 02-03/03/2009 1
Evaluation of Anomaly Detection Method based on Pattern Recognition
- Romain Fontugne
The Graduate University for Advanced Studies
- Yosuke Himura
The University of Tokyo
- Kensuke Fukuda
Evaluation of Anomaly Detection Method based on Pattern Recognition - - PowerPoint PPT Presentation
Evaluation of Anomaly Detection Method based on Pattern Recognition Romain Fontugne The Graduate University for Advanced Studies Yosuke Himura The University of Tokyo Kensuke Fukuda National Institute of Informatics CNRS-Wide
CNRS-Wide 02-03/03/2009 1
CNRS-Wide 02-03/03/2009 2
– Hough transform
CNRS-Wide 02-03/03/2009 3
– Misconfigurations, failure, network attacks
– Bandwidth consuming – Weaken network performance – Harmful traffic – Alter the traffic's characteristics
CNRS-Wide 02-03/03/2009 4
– Huge amount of data – Variety of anomalous traffic – Identification of tiny flows
– Usually treated as a statistical problem
CNRS-Wide 02-03/03/2009 5
CNRS-Wide 02-03/03/2009 6
– 2009/02/21
CNRS-Wide 02-03/03/2009 7
– Generate pictures from traffic – Hough transform – Retrieve packet information – Report anomalies
CNRS-Wide 02-03/03/2009 8
– Points elects lines – Polar coordinates
– Hough space
– Relative threshold
Original picture Hough space
CNRS-Wide 02-03/03/2009 9
– Weight for the voting procedure – Threshold to determine candidate line
– Time bin – Size of pictures
CNRS-Wide 02-03/03/2009 10
– suspected = false positive + unknown
– Lower is better
CNRS-Wide 02-03/03/2009 11
– From 2001/01 to 2006/06
CNRS-Wide 02-03/03/2009 12
(Includes many false positives)
CNRS-Wide 02-03/03/2009 13
D e s t i n a t i
i p s
r c e p
t p
t e n t r
y n b . p k t D e s t i n a t i
i p s
r c e p
t p
t e n t r
y n b . p k t
CNRS-Wide 02-03/03/2009 14
– 50% of their results in common
CNRS-Wide 02-03/03/2009 15
– Auto-tuning of parameters – Sampled data – More graphical representations – Study good combinations
CNRS-Wide 02-03/03/2009 16
CNRS-Wide 02-03/03/2009 17
CNRS-Wide 02-03/03/2009 18
D e s t i n a t i
i p s
r c e p
t p
t e n t r
y v
u m e