In recent years, network anomaly detection has become an important area for both commercial interests as well as academic research. Applications of anomaly detection typically stem from the perspectives of network monitoring and network security. In network monitoring, a service provider is often interested in capturing such network characteristics as heavy flows, flow size distributions, and the number of distinct flows. In network security, the interest lies in characterizing known or unknown anomalous patterns of an attack or a virus. In this chapter we review two main approaches to network anomaly detection: streaming algorithms, and machine learning approaches with a focus on unsupervised learning. We discuss the main features of the different approaches and discuss their pros and cons. We conclude the chapter by presenting some open problems in the area of network anomaly detection.
CITATION STYLE
Thottan, M., Liu, G., & Ji, C. (2010). Anomaly Detection Approaches for Communication Networks (pp. 239–261). https://doi.org/10.1007/978-1-84882-765-3_11
Mendeley helps you to discover research relevant for your work.