STOP-IT
  • About
    • Work Packages
    • Community of Practice and Networks
    • Frontrunners and Followers
    • Meet the Team
    • Terms and Acronyms
  • Results & Downloads
    • Tools and Technologies
    • Training Material
    • Communities of Practice
    • Dissemination Material
  • Contact us
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Paper: LADS – A Live Anomaly Detection System based on Machine Learning Methods

  • Number of downloads 33
  • File size 615.02 KB
  • Upload-Date 25. June 2020
  • Download

Abstract: Network anomaly detection using NetFlow has been widely studied during the last decade. NetFlow provides the ability to collect network traffic attributes (e.g., IP source, IP destination, source port, destination port, protocol) and allows the use of association rule mining to extract the flows that have caused a malicious event. Despite of all the developments in network anomaly detection, the most popular procedure to detect nonconformity patterns in network traffic is still manual inspection during the period under analysis (e.g., visual analysis of plots, identification of variations in the number of bytes, packets, flows). This paper presents a Live Anomaly Detection System (LADS) based on One class Support Vector Machine (One-class SVM) to detect traffic anomalies. Experiments have been conducted using a valid data-set containing over 1.4 million packets (captured using NetFlow v5 and v9) that build models with one and several features in order to identify the approach that most accurately detects traffic anomalies in our system. A multi-featured approach that restricts the analysis to one IP address and extends it in terms of samples (valid and invalid ones) is considered as a promising approach in terms of accuracy of the detected malicious instances.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
https://stop-it-project.eu/wp-content/uploads/2020/04/stopit_color_188x160px.png 0 0 Zimmermann https://stop-it-project.eu/wp-content/uploads/2020/04/stopit_color_188x160px.png Zimmermann2020-06-25 13:52:122021-07-20 11:52:30Paper: LADS – A Live Anomaly Detection System based on Machine Learning Methods

Get involved in STOP-IT

To receive project news and our newsletter, please subscribe here. By subscribing, you allow us to contact you by email and accept our privacy policy.

Community of Practice

Community of Practice Banner

Please send an email to
stopit-cop@iww-online.de
to join our Communities of Practice (COP).

Social media

    X-twitter X-twitter
EU-Flag
This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 740610. The publication reflects only the authors’ views and the European Union is not liable for any use that may be made of the information contained therein.
Logo ict4water
© Copyright - STOP-IT
  • Legal Disclaimer
  • Privacy Policy
Link to: Paper: RISKNOUGHT A Cyber-Physical Stress-Testing Platform For Water Distribution Networks Link to: Paper: RISKNOUGHT A Cyber-Physical Stress-Testing Platform For Water Distribution Networks Paper: RISKNOUGHT A Cyber-Physical Stress-Testing Platform For Water Distribution...Link to: STOP-IT Magazine Issue 3 Link to: STOP-IT Magazine Issue 3 STOP-IT Magazine Issue 3
Scroll to top Scroll to top Scroll to top