Multivariate metrics of normal and anomalous network behaviors

Nong Ye, Douglas Montgomery, Kevin Mills, Mark Carson

Research output: Chapter in Book/Report/Conference proceedingConference contribution

4 Scopus citations

Abstract

Detecting network anomalies is a fundamental part of day to day operations for Internet Service Providers and enterprises to maintain the efficiency and reliability of computer networks. Network anomaly detection is based on data characteristics of normal and anomalous network behaviors. Although many existing studies report univariate data characteristics of normal and anomalous network behaviors, there are few studies on multivariate data characteristics of normal and anomalous network behaviors. The goal of this study is to investigate multivariate data characteristics of normal and anomalous network behaviors using the Partial-Value Association Discovery (PVAD) algorithm. This paper illustrates the use of the PVAD algorithm to analyze network flow data of a medium size enterprise under the normal condition and an anomalous condition and reveal multivariate data characteristics of the normal and anomalous network flows in the form of multivariate data associations.

Original languageEnglish (US)
Title of host publication2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages55-58
Number of pages4
ISBN (Electronic)9783903176157
StatePublished - May 16 2019
Event2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019 - Arlington, United States
Duration: Apr 8 2019Apr 12 2019

Publication series

Name2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019

Conference

Conference2019 IFIP/IEEE Symposium on Integrated Network and Service Management, IM 2019
Country/TerritoryUnited States
CityArlington
Period4/8/194/12/19

Keywords

  • Data mining
  • Multivariate data characteristics of network flows
  • Network anomaly detection

ASJC Scopus subject areas

  • Information Systems and Management
  • Management Science and Operations Research
  • Information Systems
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Multivariate metrics of normal and anomalous network behaviors'. Together they form a unique fingerprint.

Cite this