Professional Documents
Culture Documents
University of Granada
SIEM
Netflow
IDS
Netflow
Firewall Netflow
logs
Hardware
monitor
Syslog
Event logs
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 2
STARTING POINT. MSNM
Anukool Lakhina, Mark Crovella, and Christophe Diot. 2004. Diagnosing network-
wide traffic anomalies. SIGCOMM Comput. Commun. Rev. 34, 4 (August 2004), 219-
230.
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 3
MSNM. COMPLETE PROCESS
New observation
loadings
Features
Observations
scores
X matrix
Detection
residuals +
X = TAPA + EA
Diagnosis
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 4
MSNM. ANOMALY DETECTION
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 5
MSNM. DIAGNOSING
Features
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 6
STANDARD MSNM DETECTION SYSTEM
SIEM
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 7
OUR PROPOSAL. HIERARCHICAL MSNM
D&Q SIEM
D&Q
D&Q
D&Q
D&Q
D&Q D&Q
D&Q
D&Q
D&Q
D&Q
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 8
LOAD REDUCTION
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 9
EXPERIMENTAL VALIDATION
Netflow inspector
Web Servers
(100 machines) 30 client machines 30 client machines
172.16.0.0/24
R3
192.168.3.0/24
30 client machines
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 11
METHODOLOGY
25 hours
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 12
RESULTS
Standard detection
Hierarchical detection
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 13
CONCLUSIONS
Hierarchical PCA-Based Multivariate Statistical Network Monitoring for Anomaly Detection - Gabriel Maci-Fernndez (Univ. Granada) 14
Thanks for your attention!