GAMPAL: Anomaly Detection for Internet Backbone Traffic by Flow Prediction with LSTM-RNN - Machine Learning for Networking
Communication Dans Un Congrès Année : 2020

GAMPAL: Anomaly Detection for Internet Backbone Traffic by Flow Prediction with LSTM-RNN

Résumé

This paper proposes a general-purpose anomaly detection mechanism for Internet backbone traffic named GAMPAL (General-purpose Anomaly detection Mechanism using Path Aggregate without Labeled data). GAMPAL does not require labeled data to achieve a general-purpose anomaly detection. For scalability to the number of entries in the BGP RIB (Routing Information Base), GAMPAL introduces path aggregates. The BGP RIB entries are classified into the path aggregates, each of which is identified with the first three AS numbers in the AS_PATH attribute. GAMPAL establishes a prediction model of traffic throughput based on past traffic throughput. It adopts the LSTM-RNN (Long Short-Term Memory Recurrent Neural Network) model focusing on periodicity in weekly scale of the Internet traffic pattern. The validity of GAMPAL is evaluated using the real traffic information and the BGP RIB exported from the WIDE backbone network (AS2500), a nation-wide backbone network for research and educational organizations in Japan. As a result, GAMPAL successfully detects traffic increases due to events and DDoS attacks targeted to a stub organization.
Fichier principal
Vignette du fichier
487577_1_En_13_Chapter.pdf (472.94 Ko) Télécharger le fichier
Origine Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03266474 , version 1 (21-06-2021)

Licence

Identifiants

Citer

Taku Wakui, Takao Kondo, Fumio Teraoka. GAMPAL: Anomaly Detection for Internet Backbone Traffic by Flow Prediction with LSTM-RNN. 2nd International Conference on Machine Learning for Networking (MLN), Dec 2019, Paris, France. pp.196-211, ⟨10.1007/978-3-030-45778-5_13⟩. ⟨hal-03266474⟩
102 Consultations
83 Téléchargements

Altmetric

Partager

More