Milcom 2006 2006
DOI: 10.1109/milcom.2006.302407
|View full text |Cite
|
Sign up to set email alerts
|

Understanding and Evaluating the Impact of Sampling on Anomaly Detection Techniques

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

1
11
0

Year Published

2009
2009
2023
2023

Publication Types

Select...
5
1

Relationship

1
5

Authors

Journals

citations
Cited by 12 publications
(12 citation statements)
references
References 9 publications
1
11
0
Order By: Relevance
“…Although some studies reported lower impacts when using flow sampling (e.g., [52,53]), Sampled NetFlow only supports packet sampling (systematic and random) [48]. Androulidakis et al [55] show that systematic sampling is especially problematic when the detection algorithms depend on the observation of a particular packet (e.g., SYN flag). Brauckhoff et al [56] also find that some anomaly detection metrics are more resilient to sampling than others, especially those based on entropy summarizations, and that detection algorithms based on packet and byte counts are less affected than those based on flow counts.…”
Section: Related Workmentioning
confidence: 99%
“…Although some studies reported lower impacts when using flow sampling (e.g., [52,53]), Sampled NetFlow only supports packet sampling (systematic and random) [48]. Androulidakis et al [55] show that systematic sampling is especially problematic when the detection algorithms depend on the observation of a particular packet (e.g., SYN flag). Brauckhoff et al [56] also find that some anomaly detection metrics are more resilient to sampling than others, especially those based on entropy summarizations, and that detection algorithms based on packet and byte counts are less affected than those based on flow counts.…”
Section: Related Workmentioning
confidence: 99%
“…In Reference [27] the impact of three packet sampling techniques (systematic, random n ‐out‐of‐ N , and uniform probabilistic random sampling) that have been proposed in the PSAMP IETF draft [28] on three widely used anomaly detection algorithms was studied and evaluated. The results revealed that systematic sampling does not perform well under low sampling rates when the detection of the attack depends on certain packet characteristics (e.g., TCP flags).…”
Section: Related Work and Discussionmentioning
confidence: 99%
“…Results showed that all sampling algorithms adversely affect both volumetric and portscan anomaly detectors. Similarly, it was shown in [13] that the accuracy of an ADS is dependent on the rate of sampling when flow-based metrics are used. Brauckhoff et al [14] analyzed the volume and feature entropy metrics and showed that packet sampling does not have much impact on volumetric packet counts but can introduce significant bias in flow counts.…”
Section: Related Work and Design Con-straintsmentioning
confidence: 92%