Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate

Y. Fukushima, T. Murase, R. Fujimaki, S. Hirose, T. Yokohira
{"title":"Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate","authors":"Y. Fukushima, T. Murase, R. Fujimaki, S. Hirose, T. Yokohira","doi":"10.1109/CQR.2009.5137356","DOIUrl":null,"url":null,"abstract":"One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts two-stage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage change-point detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.","PeriodicalId":186033,"journal":{"name":"2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability","volume":"89 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-05-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CQR.2009.5137356","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts two-stage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage change-point detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.
基于假阳性率的加权报警提高多级变点检测方案的准确性
对于大规模同时发生的事件(例如,DDoS攻击和蠕虫流行),一种有希望的方法是使用多阶段变更点检测方案。该方案采用两阶段检测。在第一阶段,部署在每个被监视子网上的本地检测器(ld)检测被监视度量(如传出流量速率)中的变化点。如果LD检测到更改点,它将向全局检测器(GD)发送警报。在第二阶段,GD检查同时发送警报的ld的比例是否大于或等于某个阈值。如果是这样,它判断正在发生大规模同时发生的事件。在以往的多阶段变点检测方案研究中,假设每个警报的权重相同。在此假设下,当某些ld频繁发送误报警报时,方案的误报率往往较高。为了降低多阶段变点检测方案的误报率,本文根据每个LD的误报率对告警进行加权。在我们的方案中,GD推断出每个LD的假阳性率,并对假阳性率较高的LD给予较低的权重。仿真结果表明,在检测率必须为1.0的约束下,我们提出的方案比没有报警加权的方案具有更低的误报率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信