Comparison of Supervised and Unsupervised Learning for Detecting Anomalies in Network Traffic

dc.contributor.authorMcAndrew, Robert
dc.contributor.authorHayne, Stephen
dc.contributor.authorWang, Haonan
dc.date.accessioned2019-01-03T00:57:13Z
dc.date.available2019-01-03T00:57:13Z
dc.date.issued2019-01-08
dc.description.abstractAdversaries are always probing for vulnerable spots on the Internet so they can attack their target. By examining traffic at the firewall, we can look for anomalies that may represent these probes. To help select the right techniques we conduct comparisons of supervised and unsupervised machine learning on network flows to find sets of outliers flagged as potential threats. We apply Functional PCA and K-Means together versus Multilayer Perceptron on a real-world dataset of traffic prior to an NTP DDoS attack in January 2014; scanning activity was heightened during this pre-attack period. We partition data to evaluate detection powers of each technique and show that FPCA+Kmeans outperforms MLP. We also present a new variation of the circle plot for visualization of resulting outliers which we suggest excels at displaying multidimensional attributes of an individual IP's behavior over time. In small multiples, circle plots show a gestalt overview of traffic.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2019.857
dc.identifier.isbn978-0-9981331-2-6
dc.identifier.urihttp://hdl.handle.net/10125/60150
dc.language.isoeng
dc.relation.ispartofProceedings of the 52nd Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Threat Intelligence and Analytics
dc.subjectSoftware Technology
dc.subjectCircle Plots, FPCA, Machine Learning, Network Anomaly Detection
dc.titleComparison of Supervised and Unsupervised Learning for Detecting Anomalies in Network Traffic
dc.typeConference Paper
dc.type.dcmiText

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0710.pdf
Size:
50.2 MB
Format:
Adobe Portable Document Format