Skip to main navigation Skip to search Skip to main content

Exploiting snmp-mib data to detect network anomalies using machine learning techniques

  • Princess Sumaya University for Technology
  • University of Mutah

Research output: Contribution to journalArticlepeer-review

5 Scopus citations

Abstract

The exponential increase in the number of malicious threats on computer networks and Internet services due to a large number of attacks makes the network security at continuous risk. One of the most prevalent network attacks that threaten networks is Denial of Service (DoS) flooding attack. DoS attacks have recently become the most attractive type of attacks to attackers and these have posed devastating threats to network services. So, there is a need for effective approaches, which can efficiently detect any intrusion in the network. This paper presents an efficient mechanism for network attacks detection and types of attack classification using the Management Information Base (MIB) database associated with the Simple Network Management Protocol (SNMP) through machine learning techniques. This paper also investigates the impact of SNMP-MIB data on network anomalies detection. Three classifiers, namely, Random Forest, AdaboostM1 and MLP are used to build the detection model. The use of different classifiers presents a comprehensive study on the effectiveness of SNMP-MIB data in detecting different types of attack. Empirical results show that the machine learning techniques were quite successful in detecting and classifying the attacks with a high detection rate.

Original languageEnglish
Pages (from-to)991-1004
Number of pages14
JournalAdvances in Intelligent Systems and Computing
Volume869
DOIs
StatePublished - 2018
Externally publishedYes

Keywords

  • Anomaly detection
  • DoS attack
  • SNMP-MIB Machine learning classifier

Fingerprint

Dive into the research topics of 'Exploiting snmp-mib data to detect network anomalies using machine learning techniques'. Together they form a unique fingerprint.

Cite this