A data mining system for distributed abnormal event detection in backbone networks

Yingjie Zhou, Guangmin Hu, Dapeng Wu

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

8 Citations (Scopus)

Abstract

Detecting distributed abnormal events has become an increasingly significant task for efficient network management and operation. However, it is still challenging to uncover these distributed behaviors in backbone networks because of the voluminous amount of noisy, high-dimensional traffic data. In this paper, we present a novel system for detecting distributed abnormal events in backbone networks. The proposed system emphasizes on detecting distributed correlated abnormal events, which are caused by the same reason. In contrast, existing methods are not able to distinguish correlated abnormal events from the independent abnormal events. In our proposed system, a set of data mining techniques is used for modeling and detecting distributed correlated abnormal events by analyzing the traffic features. Specifically, traffic behavior representation is constructed to define and select traffic features for describing the traffic behaviors of interest, feature clustering is performed to group together similar transformations in each feature, behavioral data mining is employed to discover the most significant patterns in network interactions with respect to typical behavior, and behavior classification is used to expose the behaviors of interest. Experiment results using real traffic data present the effectiveness of our proposed methods for detecting distributed correlated abnormal events in the backbone network. © 2013 John Wiley & Sons, Ltd.
Original languageEnglish
Pages (from-to)904-913
JournalSecurity and Communication Networks
Volume7
Issue number5
DOIs
Publication statusPublished - May 2014
Externally publishedYes

Bibliographical note

Publication details (e.g. title, author(s), publication statuses and dates) are captured on an “AS IS” and “AS AVAILABLE” basis at the time of record harvesting from the data source. Suggestions for further amendments or supplementary information can be sent to [email protected].

Research Keywords

  • Anomaly detection
  • Backbone networks
  • Distributed correlated abnormal event
  • Network data mining
  • Supervised learning
  • Unsupervised learning

Fingerprint

Dive into the research topics of 'A data mining system for distributed abnormal event detection in backbone networks'. Together they form a unique fingerprint.

Cite this