A Network Traffic Abnormal Detection Method: Sketch-Based Profile Evolution

3Citations
Citations of this article
8Readers
Mendeley users who have this article in their library.

Abstract

Network anomaly detection faces unique challenges from dynamic traffic, including large data volume, few attributes, and human factors that influence it, making it difficult to identify typical behavioral characteristics. To address this, we propose using Sketch-based Profile Evolution (SPE) to detect network traffic anomalies. Firstly, the Traffic Graph (TG) of the network terminal is generated using Sketch to identify abnormal data flow positions. Next, the Convolutional Neural Network and Long Short-Term Memory Network (CNN-LSTM) are used to develop traffic behavior profiles, which are then continuously updated using Evolution to detect behavior pattern changes in real-time data streams. SPE allows for direct processing of raw traffic datasets and continuous detection of constantly updated data streams. In experiments using real network traffic datasets, the SPE algorithm was found to be far more efficient and accurate than PCA and Basic Evolution for outlier detection. It is important to note that the value of φ can affect the results of anomaly detection.

Cite

CITATION STYLE

APA

Yi, J., Zhang, S., Tan, L., & Tian, Y. (2023). A Network Traffic Abnormal Detection Method: Sketch-Based Profile Evolution. Applied Sciences (Switzerland), 13(16). https://doi.org/10.3390/app13169087

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free