基于假阳性率的加权报警提高多级变点检测方案的准确性

Y. Fukushima, T. Murase, R. Fujimaki, S. Hirose, T. Yokohira
{"title":"基于假阳性率的加权报警提高多级变点检测方案的准确性","authors":"Y. Fukushima, T. Murase, R. Fujimaki, S. Hirose, T. Yokohira","doi":"10.1109/CQR.2009.5137356","DOIUrl":null,"url":null,"abstract":"One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts two-stage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage change-point detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.","PeriodicalId":186033,"journal":{"name":"2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability","volume":"89 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-05-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate\",\"authors\":\"Y. Fukushima, T. Murase, R. Fujimaki, S. Hirose, T. Yokohira\",\"doi\":\"10.1109/CQR.2009.5137356\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts two-stage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage change-point detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.\",\"PeriodicalId\":186033,\"journal\":{\"name\":\"2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability\",\"volume\":\"89 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2009-05-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CQR.2009.5137356\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CQR.2009.5137356","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

对于大规模同时发生的事件(例如,DDoS攻击和蠕虫流行),一种有希望的方法是使用多阶段变更点检测方案。该方案采用两阶段检测。在第一阶段,部署在每个被监视子网上的本地检测器(ld)检测被监视度量(如传出流量速率)中的变化点。如果LD检测到更改点,它将向全局检测器(GD)发送警报。在第二阶段,GD检查同时发送警报的ld的比例是否大于或等于某个阈值。如果是这样,它判断正在发生大规模同时发生的事件。在以往的多阶段变点检测方案研究中,假设每个警报的权重相同。在此假设下,当某些ld频繁发送误报警报时,方案的误报率往往较高。为了降低多阶段变点检测方案的误报率,本文根据每个LD的误报率对告警进行加权。在我们的方案中,GD推断出每个LD的假阳性率,并对假阳性率较高的LD给予较低的权重。仿真结果表明,在检测率必须为1.0的约束下,我们提出的方案比没有报警加权的方案具有更低的误报率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate
One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts two-stage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage change-point detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Intentional window flow control for proxy-based TCP in ad hoc networks Proof of optimal algorithm for maximum-bandwidth ALM tree construction An exact optimization tool for market-oriented grid middleware Quantifying software reliability and readiness Computational quality model for wideband voice-over-IP communications
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1