International Conference on Security and Privacy in Communication Networks. 10th International ICST Conference, SecureComm 2014, Beijing, China, September 24-26, 2014, Revised Selected Papers, Part II

Research Article

Network Traffic Pattern Analysis Using Improved Information Theoretic Co-clustering Based Collective Anomaly Detection

Download
293 downloads
  • @INPROCEEDINGS{10.1007/978-3-319-23802-9_17,
        author={Mohiuddin Ahmed and Abdun Mahmood},
        title={Network Traffic Pattern Analysis Using Improved Information Theoretic Co-clustering Based Collective Anomaly Detection},
        proceedings={International Conference on Security and Privacy in Communication Networks. 10th International ICST Conference, SecureComm 2014, Beijing, China, September 24-26, 2014, Revised Selected Papers, Part II},
        proceedings_a={SECURECOMM},
        year={2015},
        month={12},
        keywords={Network traffic analysis Information theory Co-clustering Collective anomaly detection Pattern mining},
        doi={10.1007/978-3-319-23802-9_17}
    }
    
  • Mohiuddin Ahmed
    Abdun Mahmood
    Year: 2015
    Network Traffic Pattern Analysis Using Improved Information Theoretic Co-clustering Based Collective Anomaly Detection
    SECURECOMM
    Springer
    DOI: 10.1007/978-3-319-23802-9_17
Mohiuddin Ahmed1,*, Abdun Mahmood1,*
  • 1: UNSW Canberra
*Contact email: Mohiuddin.Ahmed@student.adfa.edu.au, Abdun.Mahmood@unsw.edu.au

Abstract

Collective anomaly is a pattern in the data when a group of similar data instances behave anomalously with respect to the entire dataset. Clustering is a useful unsupervised technique to identify the underlying pattern in the data as well as anomaly detection. However, existing clustering based techniques have high false alarm rates and consider individual data instance behaviour for anomaly detection. In this paper, we formulate the problem of detecting DoS (Denial of Service) attacks as collective anomaly detection and propose a mathematically logical criteria for selecting the important traffic attributes for detecting collective anomaly. Information theoretic co-clustering algorithm is advantageous over regular clustering for creating more fine-grained representation of the data, however lacks the ability to handle mixed attribute data. We extend the co-clustering algorithm by incorporating the ability to handle categorical attributes which augments the detection accuracy of DoS attacks in benchmark KDD cup 1999 network traffic dataset than the existing techniques.