Skip to main navigation Skip to search Skip to main content

A Network Traffic Anomaly Detection Method Based on Gaussian Mixture Model

  • Bin Yu
  • , Yongzheng Zhang
  • , Wenshu Xie
  • , Wenjia Zuo
  • , Yiming Zhao
  • , Yuliang Wei*
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology
  • China Aerospace Science and Technology Corporation

Research output: Contribution to journalArticlepeer-review

Abstract

How can we learn the normal behavior of some communication processes and predict whether a single communication is under attack, with massive network traffic data representing the time costs of each stage in a single communication process? This paper introduces a statistical method for detecting network traffic anomalies using the Gaussian mixture model. There are two aspects to our contributions. First, we show how to learn the normal behavior of a communication process under the assumption that its time costs are generated from the Gaussian mixture model. Secondly, we show that with the learned Gaussian mixture model, we can predict whether a data point is under attack by computing the likelihood that the data point is drawn from the learned Gaussian distribution. The experimental results show that our method reached high accuracy in some cases, while in some other cases that are more complicated, the data point may have more factors and cannot be represented simply by only one Gaussian mixture model.

Original languageEnglish
Article number1397
JournalElectronics (Switzerland)
Volume12
Issue number6
DOIs
StatePublished - Mar 2023
Externally publishedYes

Keywords

  • Gaussian mixture model
  • anomaly detection
  • traffic data

Fingerprint

Dive into the research topics of 'A Network Traffic Anomaly Detection Method Based on Gaussian Mixture Model'. Together they form a unique fingerprint.

Cite this