메뉴 건너뛰기




Volumn 29, Issue 7, 2010, Pages 737-755

Network anomaly detection through nonlinear analysis

Author keywords

Anomaly detection; Non stationarity; Nonlinear analysis; Recurrence quantification analysis; Support vector machines

Indexed keywords

ANOMALOUS BEHAVIOR; ANOMALY DETECTION; ATTACK MECHANISM; IP TRAFFIC FLOWS; NETWORK ANOMALIES; NETWORK ANOMALY DETECTION; NETWORK TRAFFIC; NETWORK-BASED; NON-STATIONARITIES; NONLINEAR TECHNIQUES; NONSTATIONARY; NORMAL BEHAVIOR; RECURRENCE QUANTIFICATION ANALYSIS; STATISTICAL PROPERTIES; STRUCTURAL PARTS; SYSTEM VULNERABILITY; THREATS AND ATTACKS; TIME CORRELATIONS; TRAFFIC ANOMALIES; TRAFFIC DYNAMICS; TRAFFIC PATTERN; TRAFFIC TIME SERIES; TRANSITION PATTERNS;

EID: 77956393826     PISSN: 01674048     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.cose.2010.05.002     Document Type: Article
Times cited : (68)

References (60)
  • 4
    • 1642535783 scopus 로고    scopus 로고
    • A novel approach to detection of denial-of-service attacks via adaptive sequential and batch-sequential change-point detection methods
    • R.B. Blazek, H. Kim, B. Rozovskii, and A. Tartakovsky A novel approach to detection of denial-of-service attacks via adaptive sequential and batch-sequential change-point detection methods IEEE workshop information assurance and security 2001 220 226
    • (2001) IEEE Workshop Information Assurance and Security , pp. 220-226
    • Blazek, R.B.1    Kim, H.2    Rozovskii, B.3    Tartakovsky, A.4
  • 5
    • 0036967463 scopus 로고    scopus 로고
    • Use of spectral analysis in defence against DoS attacks
    • C.M. Cheng, H.T. Kung, and K.S. Tan Use of spectral analysis in defence against DoS attacks IEEE GLOBECOM 2002 2143 2148
    • (2002) IEEE GLOBECOM , pp. 2143-2148
    • Cheng, C.M.1    Kung, H.T.2    Tan, K.S.3
  • 6
  • 7
    • 44949273552 scopus 로고
    • State space reconstruction in the presence of noise
    • M. Casdagli, S. Eubank, J.D. Farmer, and J. Gibson State space reconstruction in the presence of noise Phys D 51 1991 52 98
    • (1991) Phys D , vol.51 , pp. 52-98
    • Casdagli, M.1    Eubank, S.2    Farmer, J.D.3    Gibson, J.4
  • 10
    • 35949018382 scopus 로고
    • Ergodic theory of chaos and strange attractors
    • J.P. Eckmann, and D. Ruelle Ergodic theory of chaos and strange attractors Rev Mod Phys 1985 617 656
    • (1985) Rev Mod Phys , pp. 617-656
    • Eckmann, J.P.1    Ruelle, D.2
  • 12
    • 34548696055 scopus 로고
    • Independent coordinates for strange attractors from mutual information
    • A.M. Fraser, and H.L. Swinney Independent coordinates for strange attractors from mutual information Phys Rev A 33 2 1986 1134 1140
    • (1986) Phys Rev A , vol.33 , Issue.2 , pp. 1134-1140
    • Fraser, A.M.1    Swinney, H.L.2
  • 14
    • 33646981873 scopus 로고
    • Characterization of strange attractors
    • P. Grassberger, and I. Procaccia Characterization of strange attractors Phys Rev Lett 50 5 1983
    • (1983) Phys Rev Lett , vol.50 , Issue.5
    • Grassberger, P.1    Procaccia, I.2
  • 15
    • 84878701863 scopus 로고    scopus 로고
    • Detecting anomalies in network traffic using maximum entropy estimation
    • Y. Gu, A. McCallum, and D. Towsley Detecting anomalies in network traffic using maximum entropy estimation IMC Conference 2005
    • (2005) IMC Conference
    • Gu, Y.1    McCallum, A.2    Towsley, D.3
  • 17
    • 0000810560 scopus 로고    scopus 로고
    • Practical implementation of non linear time series method: TISEAN package
    • R. Hegger, H. Kantz, and T. Schreiber Practical implementation of non linear time series method: TISEAN package Chaos 9 1999 413 435
    • (1999) Chaos , vol.9 , pp. 413-435
    • Hegger, R.1    Kantz, H.2    Schreiber, T.3
  • 19
    • 11944266815 scopus 로고
    • Direct test for determinism in a time series
    • D.T. Kaplan, and L. Glass Direct test for determinism in a time series Phys Rev Lett 68 1992 427 430
    • (1992) Phys Rev Lett , vol.68 , pp. 427-430
    • Kaplan, D.T.1    Glass, L.2
  • 20
    • 0001870258 scopus 로고
    • A robust method to estimate the maximal Lyapunov exponent of a time series
    • H. Kantz A robust method to estimate the maximal Lyapunov exponent of a time series Phys Lett A 185 1994 77 87
    • (1994) Phys Lett A , vol.185 , pp. 77-87
    • Kantz, H.1
  • 21
    • 35949006791 scopus 로고
    • Determing embedding dimension for phase space reconstruction using a geometrical construction
    • M. Kennel, R. Brown, and H. Abarbanel Determing embedding dimension for phase space reconstruction using a geometrical construction Phys Rev A 45 1992 3403 3411
    • (1992) Phys Rev A , vol.45 , pp. 3403-3411
    • Kennel, M.1    Brown, R.2    Abarbanel, H.3
  • 25
    • 0034301517 scopus 로고    scopus 로고
    • Analysis and results of the 1999 DARPA off-line intrusion detection evaluation
    • R. Lippmann, J. Haines, D. Fried, J. Korba, and K. Das Analysis and results of the 1999 DARPA off-line intrusion detection evaluation Computer Networks 34 4 2000 579 595
    • (2000) Computer Networks , vol.34 , Issue.4 , pp. 579-595
    • Lippmann, R.1    Haines, J.2    Fried, D.3    Korba, J.4    Das, K.5
  • 29
    • 0242456801 scopus 로고    scopus 로고
    • Learning nonstationary models of normal network traffic for detecting novel attacks
    • M. Mahoney, and P.K. Chan Learning nonstationary models of normal network traffic for detecting novel attacks Edmonton, Alberta: Proceedings SIGKDD 2002 376 385
    • (2002) Edmonton, Alberta: Proceedings SIGKDD , pp. 376-385
    • Mahoney, M.1    Chan, P.K.2
  • 30
    • 0037661195 scopus 로고    scopus 로고
    • Network traffic anomaly detection based on packet bytes
    • M. Mahoney Network traffic anomaly detection based on packet bytes Proceedings ACM-SAC 2003 346 350
    • (2003) Proceedings ACM-SAC , pp. 346-350
    • Mahoney, M.1
  • 31
    • 33845439009 scopus 로고    scopus 로고
    • Multi-fractal analysis of IP-network traffic for assessing time variations in scaling properties
    • M. Masugi, and T. Takuma Multi-fractal analysis of IP-network traffic for assessing time variations in scaling properties Phys D 225 2007 119 126
    • (2007) Phys D , vol.225 , pp. 119-126
    • Masugi, M.1    Takuma, T.2
  • 32
    • 33846338227 scopus 로고    scopus 로고
    • Recurrence plots for the analysis of complex systems
    • N. Marwan, M.C. Romano, M. Thiel, and J. Kurths Recurrence plots for the analysis of complex systems Phys Reports 438 2007 237 329
    • (2007) Phys Reports , vol.438 , pp. 237-329
    • Marwan, N.1    Romano, M.C.2    Thiel, M.3    Kurths, J.4
  • 33
    • 0037201218 scopus 로고    scopus 로고
    • Nonlinear analysis of bivariate data with cross recurrence plots
    • N. Marwan, and J. Kurths Nonlinear analysis of bivariate data with cross recurrence plots Phys Lett A 302 2002 299 307
    • (2002) Phys Lett A , vol.302 , pp. 299-307
    • Marwan, N.1    Kurths, J.2
  • 38
    • 44049112233 scopus 로고
    • Distinguishing between low-dimensional dynamics and randomness in measured time series
    • A. Provenzale, L.A. Smith, R. Vio, and G. Murante Distinguishing between low-dimensional dynamics and randomness in measured time series Phys D 58 1992 31 49
    • (1992) Phys D , vol.58 , pp. 31-49
    • Provenzale, A.1    Smith, L.A.2    Vio, R.3    Murante, G.4
  • 39
    • 0001285133 scopus 로고
    • Deterministic chaos: The science and the fiction
    • D. Ruelle Deterministic chaos: the science and the fiction Proc R Soc Lond A 427 1990 241 248
    • (1990) Proc R Soc Lond A , vol.427 , pp. 241-248
    • Ruelle, D.1
  • 40
    • 77956392436 scopus 로고    scopus 로고
    • RQA 10.1.
    • RQA 10.1. http://homepages.luc.edu/∼cwebber.
  • 41
    • 18144385431 scopus 로고    scopus 로고
    • Application of anomaly detection algorithms for detecting SYN flooding attacks
    • V.A. Siris, and F. Papagalou Application of anomaly detection algorithms for detecting SYN flooding attacks IEEE GLOBECOM 2004 2050 2054
    • (2004) IEEE GLOBECOM , pp. 2050-2054
    • Siris, V.A.1    Papagalou, F.2
  • 42
    • 18144385431 scopus 로고    scopus 로고
    • Application of anomaly detection algorithms for detecting SYN flooding attacks
    • V.A. Siris, and F. Papagalou Application of anomaly detection algorithms for detecting SYN flooding attacks Global Telecommun Conf 29 3 2004 2050 2054
    • (2004) Global Telecommun Conf , vol.29 , Issue.3 , pp. 2050-2054
    • Siris, V.A.1    Papagalou, F.2
  • 49
    • 0032069395 scopus 로고    scopus 로고
    • Phase transition pattern in a computer network
    • A. Tretyakov, H. Takayasu, and M. Takayasu Phase transition pattern in a computer network Phys A 253 1998 315 322
    • (1998) Phys A , vol.253 , pp. 315-322
    • Tretyakov, A.1    Takayasu, H.2    Takayasu, M.3
  • 50
    • 0033887834 scopus 로고    scopus 로고
    • Dynamic phase transition observed in the Internet traffic flow
    • M. Takayasu, H. Takayasu, and K. Fukuda Dynamic phase transition observed in the Internet traffic flow Phys A 277 2000 248 255
    • (2000) Phys A , vol.277 , pp. 248-255
    • Takayasu, M.1    Takayasu, H.2    Fukuda, K.3
  • 52
    • 0003278979 scopus 로고    scopus 로고
    • Is network traffic self-similar or multifractal?
    • M.S. Taqqu, V. Teverovsky, and W. Willinger Is network traffic self-similar or multifractal? Fractals 5 1997 63
    • (1997) Fractals , vol.5 , pp. 63
    • Taqqu, M.S.1    Teverovsky, V.2    Willinger, W.3
  • 53
    • 54049125096 scopus 로고    scopus 로고
    • Unsupervised anomaly detection using HDG-Clustering algorithm
    • C.F. Tsai, and C.C. Yen Unsupervised anomaly detection using HDG-Clustering algorithm Lecture Notes Comp Sci 4985 2008 356 365
    • (2008) Lecture Notes Comp Sci , vol.4985 , pp. 356-365
    • Tsai, C.F.1    Yen, C.C.2
  • 54
    • 0000779360 scopus 로고
    • Detecting strange attractors in fluid turbulence
    • F. Takens Detecting strange attractors in fluid turbulence D. Rand, L.S. Young, Dynamical systems and turbulence 1981 Springer 366 381
    • (1981) Dynamical Systems and Turbulence , pp. 366-381
    • Takens, F.1
  • 58
    • 0028354598 scopus 로고
    • Dynamical assessment of physiological system and status using recurrence plot strategies
    • C.L. Webber Jr., and J.P. Zbilut Dynamical assessment of physiological system and status using recurrence plot strategies J Appl Physiol 76 1994 965 973
    • (1994) J Appl Physiol , vol.76 , pp. 965-973
    • Webber Jr., C.L.1    Zbilut, J.P.2
  • 59
    • 0000688735 scopus 로고
    • Embeddings and delays as derived from recurrence quantification analysis
    • J.P. Zbilut, and C.L. Webber Embeddings and delays as derived from recurrence quantification analysis Phys Lett A 171 1992 199 203
    • (1992) Phys Lett A , vol.171 , pp. 199-203
    • Zbilut, J.P.1    Webber, C.L.2
  • 60
    • 0042357254 scopus 로고    scopus 로고
    • Recurrence quantification analysis and principal components in the detection of short complex signals
    • J.P. Zbilut, A. Giuliani, and C.L. Webber Jr. Recurrence quantification analysis and principal components in the detection of short complex signals Phys Lett A 237 1998 131 135
    • (1998) Phys Lett A , vol.237 , pp. 131-135
    • Zbilut, J.P.1    Giuliani, A.2    Webber Jr., C.L.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.