首页> 外文会议>IEEE International Workshop Technical Committee on Communications Quality and Reliability (CQR 2009) >Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate
【24h】

Accuracy improvement of multi-stage change-point detection scheme by weighting alerts based on false-positive rate

机译:通过基于假阳性率的警报加权来提高多阶段变化点检测方案的精度

获取原文
获取原文并翻译 | 示例

摘要

One promising approach for large-scale simultaneous events (e.g., DDoS attacks and worm epidemics) is to use a multi-stage change-point detection scheme. The scheme adopts two-stage detection. In the first stage, local detectors (LDs), which are deployed on each monitored subnet, detects a change point in a monitored metric such as outgoing traffic rate. If an LD detects a change-point, it sends an alert to global detector (GD). In the second stage, GD checks whether the proportion of LDs that send alerts simultaneously is greater than or equal to a threshold value. If so, it judges that large-scale simultaneous events are occurring. In previous studies for the multi-stage change-point detection scheme, it is assumed that weight of each alert is identical. Under this assumption, false-positive rate of the scheme tends to be high when some LDs sends false-positive alerts frequently. In this paper, we weight alerts based on false-positive rate of each LD in order to decrease false-positive rate of the multi-stage change-point detection scheme. In our scheme, GD infers false-positive rate of each LD and gives lower weight to LDs with higher false-positive rate. Simulation results show that our proposed scheme can achieve lower false-positive rate than the scheme without alert weighting under the constraint that detection rate must be 1.0.
机译:大规模同时发生事件(例如DDoS攻击和蠕虫流行)的一种有前途的方法是使用多阶段更改点检测方案。该方案采用两阶段检测。在第一阶段,部署在每个受监视子网中的本地检测器(LD)会检测受监视指标(例如传出流量速率)中的变化点。如果LD检测到更改点,它将向全局检测器(GD)发送警报。在第二阶段,GD检查同时发送警报的LD的比例是否大于或等于阈值。如果是这样,它将判断正在发生大规模同时发生的事件。在先前对多阶段变化点检测方案的研究中,假设每个警报的权重是相同的。在此假设下,当某些LD频繁发送误报警报时,该方案的误报率趋于较高。在本文中,我们基于每个LD的误报率对警报进行加权,以降低多阶段变更点检测方案的误报率。在我们的方案中,GD可以推断每个LD的假阳性率,并给具有较高假阳性率的LD较低的权重。仿真结果表明,在检测率必须为1.0的情况下,该方案与没有预警权重的方案相比,可以实现较低的假阳性率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号