A network traffic anomaly detection method based on adaptive filter is proposed to detect all kinds of network traffic attacks. Multiple network traffic indicators are predicted by recursive least square and the allowable statistical range based on the prediction errors are used to detect anomaly. Detection results are finally normalized. The method has the following traits: no training from any historical data
reducing the number of alarms
remarkably
and highlighting the severity of alarms. Testing results on DARPA intrusion detection data sets show that the proposed method is more suitable to detect denial of service attacks
and has a higher detection rate
faster speed and lower alarm rate than similar existing methods with same dimension of weight vectors.
YAO Tingting, ZHENG Qinghua, GUAN Xiaohong,et al. Security evaluation method based on real time traffic of hosts [J]. Journal of Xi'an Jiaotong University, 2006, 40(4): 415-419.
CAO Xiaomei,HAN Zhijie, CHEN Guihai. DoS attack detection scheme for sensor networks based on traffic prediction [J]. Chinese Journal of Computers, 2007, 30(10): 1798-1805.
ZARE M H, MASNADI-SHIRAZI M A. Arima model for network traffic prediction and anomaly detection[C]∥Proceedings of ITSim International Symposium on Information Technology. Piscataway, NJ, USA: IEEE, 2008:1-6.
VOELKER M D, SAVAGE S G M. Inferring internet denial-of-service activity [C]∥Proceeding of the 10th USENIX Security Symposium. Berkeley, CA, USA: The Advanced Computing Systems Association, 2001:9-22.
Massachusetts Institute of Technology. Lincoln. Laboratory. DARPA intrusion detection evaluation[EB/OL].(2008-06-01)[2009-03-02]. http:∥www.ll.mit.edu/IST/ideval/data/data-index.html.
AUGUSTIN S, KAVE S, NINA T. Combining filtering and statistical methods for anomaly detection [C]∥Prceedings of USENIX Association Internet Measurement Conference. Berkeley, CA, USA: The Advanced Computing Systems Association, 2005:331-344.