English

Network Anomaly Detection: A Survey and Comparative Analysis of Stochastic and Deterministic Methods

Machine Learning 2013-09-20 v1 Machine Learning Networking and Internet Architecture

Abstract

We present five methods to the problem of network anomaly detection. These methods cover most of the common techniques in the anomaly detection field, including Statistical Hypothesis Tests (SHT), Support Vector Machines (SVM) and clustering analysis. We evaluate all methods in a simulated network that consists of nominal data, three flow-level anomalies and one packet-level attack. Through analyzing the results, we point out the advantages and disadvantages of each method and conclude that combining the results of the individual methods can yield improved anomaly detection results.

Keywords

Cite

@article{arxiv.1309.4844,
  title  = {Network Anomaly Detection: A Survey and Comparative Analysis of Stochastic and Deterministic Methods},
  author = {Jing Wang and Daniel Rossell and Christos G. Cassandras and Ioannis Ch. Paschalidis},
  journal= {arXiv preprint arXiv:1309.4844},
  year   = {2013}
}

Comments

7 pages. 1 more figure than final CDC 2013 version

R2 v1 2026-06-22T01:29:56.464Z