2017/11/24 by Atef Abdelkefi, Yuming Jiang, Abdelkefi, Atef +3
Computer Science · #Anomaly Detection Techniques and Applications #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI)
paper · pdf · doi:10.48550/arxiv.1711.09008
openalex publication_date 2017/11/24 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
In this paper, we propose a novel approach, called SENATUS, for joint traffic\nanomaly detection and root-cause analysis. Inspired from the concept of a\nsenate, the key idea of the proposed approach is divided into three stages:\nelection, voting and decision. At the election stage, a small number of\n noptraffic flow sets (termed as senator flows)senator flows are chosen nop,\nwhich are used to represent approximately the total (usually huge) set of\ntraffic flows. In the voting stage, anomaly detection is applied on the senator\nflows and the detected anomalies are correlated to identify the most possible\nanomalous time bins. Finally in the decision stage, a machine learning\ntechnique is applied to the senator flows of each anomalous time bin to find\nthe root cause of the anomalies. We evaluate SENATUS using traffic traces\ncollected from the Pan European network, GEANT, and compare against another\napproach which detects anomalies using lossless compression of traffic\nhistograms. We show the effectiveness of SENATUS in diagnosing anomaly types:\nnetwork scans and DoS/DDoS attacks.\n