Design and Implementation of Parallel Anomaly Detection
The main objective of the thesis is to show that multiple anomaly detection algorithms can be implemented in parallel to effectively characterize the type of traffic causing the abnormal behavior. The logs are obtained by running six anomaly detection algorithms in parallel on the Network Processor....
Main Author: | |
---|---|
Format: | Others |
Published: |
ScholarWorks@UMass Amherst
2007
|
Subjects: | |
Online Access: | https://scholarworks.umass.edu/theses/58 https://scholarworks.umass.edu/cgi/viewcontent.cgi?article=1093&context=theses |
Summary: | The main objective of the thesis is to show that multiple anomaly detection algorithms can be implemented in parallel to effectively characterize the type of traffic causing the abnormal behavior. The logs are obtained by running six anomaly detection algorithms in parallel on the Network Processor. Further, a hierarchical tree representation is defined which illustrates the state of traffic in real-time. The nodes represent a particular subset of traffic and each of the nodes calculate the aggregate for the traffic represented by the node, given the output from all the algorithms. The greater the aggregate, the darker the node indicating an anomaly. The visual representation makes it easy for an operator to distinguish between anomalous and non-anomalous nodes. |
---|