Please use this identifier to cite or link to this item: https://hdl.handle.net/2440/61936
Citations
Scopus Web of ScienceĀ® Altmetric
?
?
Full metadata record
DC FieldValueLanguage
dc.contributor.authorEriksson, B.-
dc.contributor.authorBarfold, P.-
dc.contributor.authorBowden, R.-
dc.contributor.authorDuffield, N.-
dc.contributor.authorSommers, J.-
dc.contributor.authorRoughan, M.-
dc.contributor.editorAllman, M.-
dc.date.issued2010-
dc.identifier.citationInternet Measurement Conference, held in Melbourne Australia 1-3 November 2010-
dc.identifier.isbn9781450300575-
dc.identifier.urihttp://hdl.handle.net/2440/61936-
dc.description.abstractThe ability to detect unexpected events in large networks can be a significant benefit to daily network operations. A great deal of work has been done over the past decade to develop effective anomaly detection tools, but they remain virtually unused in live network operations due to an unacceptably high false alarm rate. In this paper, we seek to improve the ability to accurately detect unexpected network events through the use of BasisDetect, a flexible but precise modeling framework. Using a small dataset with labelled anomalies, the BasisDetect framework allows us to define large classes of anomalies and detect them in different types of network data, both from single sources and from multiple, potentially diverse sources. Network anomaly signal characteristics are learned via a novel basis pursuit based methodology. We demonstrate the feasibility of our BasisDetect framework method and compare it to previous detection methods using a combination of synthetic and real-world data. In comparison with previous anomaly detection methods, our BasisDetect methodology results show a 50% reduction in the number of false alarms in a single node dataset, and over 65% reduction in false alarms for synthetic network-wide data.-
dc.description.statementofresponsibilityBrian Eriksson, Paul Barford, Rhys Bowden, Nicholas Duffield, Joel Sommers and Matthew Roughan-
dc.language.isoen-
dc.publisherACM-
dc.rightsCopyright 2010 ACM-
dc.source.urihttp://conferences.sigcomm.org/imc/2010/imc-papers.html-
dc.subjectAnomaly Detection-
dc.titleBasisDetect: A model-based network event detection framework-
dc.typeConference paper-
dc.contributor.conferenceInternet Measurement Conference (2010 : Melbourne, Australia)-
dc.identifier.doi10.1145/1879141.1879200-
dc.publisher.placeAustralia-
pubs.publication-statusPublished-
dc.identifier.orcidRoughan, M. [0000-0002-7882-7329]-
Appears in Collections:Aurora harvest
Mathematical Sciences publications

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.