Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate

Yukinobu Fukushima, Tutomu Murase, Ryohei Fujimaki, Syunsuke Hirose, Tokumi Yokohira

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Citation (Scopus)

Abstract

One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts twostage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage changepoint detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.

Original languageEnglish
Title of host publication2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009
DOIs
Publication statusPublished - 2009
Event2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009 - Naples, FL, United States
Duration: May 12 2009May 14 2009

Publication series

Name2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009

Other

Other2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009
CountryUnited States
CityNaples, FL
Period5/12/095/14/09

Keywords

  • Alert weighting
  • Large-scale simultaneous events
  • Multi-stage change-point detection scheme

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Safety, Risk, Reliability and Quality

Fingerprint Dive into the research topics of 'Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate'. Together they form a unique fingerprint.

  • Cite this

    Fukushima, Y., Murase, T., Fujimaki, R., Hirose, S., & Yokohira, T. (2009). Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate. In 2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009 [5137356] (2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009). https://doi.org/10.1109/CQR.2009.5137356