MAWILab : Combining Diverse Anomaly Detectors for Automated Anomaly Labeling and Performance Benchmarking

Abstract : Evaluating anomaly detectors is a crucial task in traffic monitoring made particularly difficult due to the lack of ground truth. The goal of the present article is to assist researchers in the evaluation of detectors by providing them with labeled anomaly traffic traces. We aim at automatically finding anomalies in the MAWI archive using a new methodology that combines different and independent detectors. A key challenge is to compare the alarms raised by these detectors, though they operate at different traffic granularities. The main contribution is to propose a reliable graph-based methodology that combines any anomaly detector outputs. We evaluated four unsupervised combination strategies; the best is the one that is based on dimensionality reduction. The synergy between anomaly detectors permits to detect twice as many anomalies as the most accurate detector, and to reject numerous false positive alarms reported by the detectors. Significant anomalous traffic features are extracted from reported alarms, hence the labels assigned to theMAWI archive are concise. The results on the MAWI traffic are publicly available and updated daily. Also, this approach permits to include the results of upcoming anomaly detectors so as to improve over time the quality and variety of labels.
Type de document :
Communication dans un congrès
ACM CoNEXT 2010, Nov 2010, Philadelphia, United States. ACM, 2010
Liste complète des métadonnées

https://hal-ens-lyon.archives-ouvertes.fr/ensl-00552071
Contributeur : Pierre Borgnat <>
Soumis le : mercredi 5 janvier 2011 - 13:31:06
Dernière modification le : jeudi 19 avril 2018 - 14:54:03
Document(s) archivé(s) le : mercredi 6 avril 2011 - 02:51:43

Fichier

conext2010_1569335085_final.pd...
Fichiers produits par l'(les) auteur(s)

Identifiants

  • HAL Id : ensl-00552071, version 1

Collections

Citation

Romain Fontugne, Pierre Borgnat, Patrice Abry, Kensuke Fukuda. MAWILab : Combining Diverse Anomaly Detectors for Automated Anomaly Labeling and Performance Benchmarking. ACM CoNEXT 2010, Nov 2010, Philadelphia, United States. ACM, 2010. 〈ensl-00552071〉

Partager

Métriques

Consultations de la notice

246

Téléchargements de fichiers

190