IEICE Communications Express
Online ISSN : 2187-0136
ISSN-L : 2187-0136

This article has now been updated. Please use the final version.

Performance Evaluation of Sketch Schemes on Traffic Anomaly Detection Accuracy
Masamichi YoshiokaTakefumi HiraguriHideaki Yoshino
Author information
JOURNAL FREE ACCESS Advance online publication

Article ID: 2017XBL0032

Details
Abstract

Network monitoring for high-speed networks shared by an increasing amount of traffic has become a crucial issue. Especially, traffic anomaly detection technology for high-speed networks is one of the most important issues, because of the increasingly serious nature of cyber-attacks such as worms, port scans, and DDoS. This study focuses on the use of sketch schemes as data reduction methods for traffic anomaly detection. Previous studies on sketch schemes neglected to fully clarify the impact of the sketch parameters on the anomaly detection performance. This study verified the processing time and traffic anomaly detection accuracy with a sketch as a function of two sketch parameters: the number of hash functions and hash table size. The range of the two sketch parameters was clarified by determining the processing time and F-measure, which evaluates both the false positive and false negative rates.

Content from these authors
© 2017 The Institute of Electronics, Information and Communication Engineers
feedback
Top