Large-scale IP network data analysis for anomalies detection thanks to SVM
Free (open access)
Volume 11 (2016), Issue 3
376 - 386
C. BENHAMED, S. MEKAOUI & K. GHOUMID
An SVM (Support Machine Vector) algorithm has been implemented to sense traffic anomalies through a large- scale IP Network. We have applied this algorithm on data provided by the well-known large-scale American IP Network (Abilene Network). The developed SVM algorithm can classify the Network traffic into two cat- egories of classes namely: normal; and abnormal. The implementation of this algorithm has been performed on real collected data thanks to Netflow protocol and has yielded satisfactory results with a classification rate going over 96% and a false alarms rate lower than 10%.
anomaly detection, genetic algorithms – SMO, IP network- supervised learning, support vector machines (SVM), true negative ratio, true positive ratio