Open Access
Subscription Access
An Effective Anomaly Traffic Detection System via Quadruple Attributes for NTU Campus Network
Abstract
The evolution of network at tacks becomes unpredictable due to the prevalence of the Internet and the increasing of network bandwidth. From our network logs, we can observe that many anomalies do not target at a specific port and new anomalies are arising swiftly without specific signatures. Thus, the approaches of monitoring some specific ports and inspecting packet content for detection of anomaly signatures, adopted in our current campus network anomaly detection systems, is insufficient. This paper proposes a network anomaly diagnosis mechanism that is aimed at detecting suspicious host behaviors before the breakout of the attacks/or anomalies. It employs four levels of attributes to describe the network traffic characteristics of the hosts. This mechanism successfully detects and separates anomaly traffic such as P2P applications, network attacks, and stealthy backdoors, which fail to be detected by current port based traffic monitoring systems commonly deployed in campus network. The proposed mechanism successfully complements the current campus-wide network anomaly detection systems.
Keywords
Network anomaly detection; Clustering; Anomaly-based detection; P2P pattern detection
Citation Format:
Mei-Wen Li, Wei-Yen Day, Phone Lin, Hsin-Hsi Chen, "An Effective Anomaly Traffic Detection System via Quadruple Attributes for NTU Campus Network," Journal of Internet Technology, vol. 10, no. 5 , pp. 497-503, Oct. 2009.
Mei-Wen Li, Wei-Yen Day, Phone Lin, Hsin-Hsi Chen, "An Effective Anomaly Traffic Detection System via Quadruple Attributes for NTU Campus Network," Journal of Internet Technology, vol. 10, no. 5 , pp. 497-503, Oct. 2009.
Full Text:
PDFRefbacks
- There are currently no refbacks.
Published by Executive Committee, Taiwan Academic Network, Ministry of Education, Taipei, Taiwan, R.O.C
JIT Editorial Office, Office of Library and Information Services, National Dong Hwa University
No. 1, Sec. 2, Da Hsueh Rd., Shoufeng, Hualien 974301, Taiwan, R.O.C.
Tel: +886-3-931-7314 E-mail: jit.editorial@gmail.com