Research Article

Network-Wide Traffic Anomaly Detection and Localization Based on Robust Multivariate Probabilistic Calibration Model

Table 6

Comparisons of RMPCM and PCA test results on DETERLab.
(a) Initial settings

Preset anomaly cyclesAlerts cyclesType
RMPCMPCA

500~503501~503502, 503DoS
800~804801801Port scan
1000~10031000~10031000~1003DoS
1200~12391200~12391217, 1231–1239Ingress/egress shift
1500~15051501~15051501~1505DDoS
1800~18031802, 18031803DoS

(b) After adjusting settings

Preset anomaly cyclesAlerts cyclesType
RMPCMPCA

500~503503502, 503DoS
800~804Port scan
1000~10031001, 10021001, 1002DoS
1200~12191200~12191200~1219, 1272Ingress/egress shift
1500~15051503, 15041407, 1416, 1451, 1503, 1504, 1637, 1665DDoS
1800~180318021701, 1733, 1814, 1849DoS

(c) Injecting the large anomaly

Preset anomaly cyclesAlerts cyclesType
RMPCMPCA

500~503500~503500~503DoS
800~804801801Port scan
1000~10031001, 1002DoS
1200~12391200~1239Ingress/egress shift
1500~15051501~15041502~1504DDoS
1800~18031801, 18031801~1803DoS