Halil Ertan, Selver Ezgi Küçükbay, Amir Yavariabdi, Nuri Kangöz, Ali Emre Tiryaki, Iren Berk Özalp
{"title":"Anomaly Detection on Broadband Network Gateway","authors":"Halil Ertan, Selver Ezgi Küçükbay, Amir Yavariabdi, Nuri Kangöz, Ali Emre Tiryaki, Iren Berk Özalp","doi":"10.1109/BlackSeaCom48709.2020.9234957","DOIUrl":null,"url":null,"abstract":"Anomaly detection in Digital Subscriber Line (DSL) networks is a vital task to immediately detect unusual network behavior caused by cyber security threats, faulty hardware or software. Generally, to make this process automatic, state-of-the-art methods use machine learning techniques to analyze data collected from either Customer Premises Equipment (CPE) or from devices in Access Network. In contrast to the existing methods, this paper utilizes network traffic data collected from multiple static Broadband Network Gateways (BNGs) which are core network devices at Network Service Provider (NSP). To automatically detect anomalies in BNG traffic data, a new framework is proposed which consists of three steps: data acquisition, feature extraction, and modeling anomalies using a random forest-based framework. The proposed method is compared with state-of-the-art methods and the results show the effectiveness and robustness of our method.","PeriodicalId":186939,"journal":{"name":"2020 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom)","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-05-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BlackSeaCom48709.2020.9234957","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Anomaly detection in Digital Subscriber Line (DSL) networks is a vital task to immediately detect unusual network behavior caused by cyber security threats, faulty hardware or software. Generally, to make this process automatic, state-of-the-art methods use machine learning techniques to analyze data collected from either Customer Premises Equipment (CPE) or from devices in Access Network. In contrast to the existing methods, this paper utilizes network traffic data collected from multiple static Broadband Network Gateways (BNGs) which are core network devices at Network Service Provider (NSP). To automatically detect anomalies in BNG traffic data, a new framework is proposed which consists of three steps: data acquisition, feature extraction, and modeling anomalies using a random forest-based framework. The proposed method is compared with state-of-the-art methods and the results show the effectiveness and robustness of our method.