Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate

Yukinobu Fukushima, Tutomu Murase, Ryohei Fujimaki, Syunsuke Hirose, Tokumi Yokohira

研究成果

1 被引用数 (Scopus)

抄録

One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts twostage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage changepoint detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.

本文言語English
ホスト出版物のタイトル2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009
DOI
出版ステータスPublished - 2009
イベント2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009 - Naples, FL
継続期間: 5月 12 20095月 14 2009

出版物シリーズ

名前2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009

Other

Other2009 IEEE International Workshop Technical Committee on Communications Quality and Reliability, CQR 2009
国/地域United States
CityNaples, FL
Period5/12/095/14/09

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • 安全性、リスク、信頼性、品質管理

フィンガープリント

「Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル