• Home
  • Search
  • Network security and anomaly detection with Big-DAMA, a big data analytics framework
  • Cite Icon42
  • https://doi.org/10.1109/cloudnet.2017.8071525Copy DOI Icon

Network security and anomaly detection with Big-DAMA, a big data analytics framework

  • Sep 1, 2017
  • Pedro Casas +4 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The complexity of the Internet and the volume of network traffic have dramatically increased in the last few years, making it more challenging to design scalable Network Traffic Monitoring and Analysis (NTMA) systems. Critical NTMA applications such as the detection of network attacks and anomalies require fast mechanisms for on-line analysis of thousands of events per second, as well as efficient techniques for off-line analysis of massive historical data. The high-dimensionality of network data provided by current network monitoring systems opens the door to the massive application of machine learning approaches to improve the detection and classification of network attacks and anomalies, but this higher dimensionality comes with an extra data processing overhead. In this paper we present Big-DAMA, a big data analytics framework (BDAF) for NTMA applications. Big-DAMA is a flexible BDAF, capable to analyze and store big amounts of both structured and unstructured heterogeneous data sources, with both stream and batch processing capabilities. Big-DAMA uses off-the-shelf big data storage and processing engines to offer both stream data processing and batch processing capabilities, decomposing separate engines for stream, batch and query, following a Data Stream Warehouse (DSW) paradigm. Big-DAMA implements several algorithms for anomaly detection and network security using supervised and unsupervised machine learning (ML) models, using off-the-shelf ML libraries. We apply Big-DAMA to the detection of different types of network attacks and anomalies, benchmarking multiple supervised ML models. Evaluations are conducted on top of real network measurements collected at the WIDE backbone network, using the well-known MAWILab dataset for attacks labeling. Big-DAMA can speed up computations by a factor of 10 when compared to a standard Apache Spark cluster, and can be easily deployed in cloud environments, using hardware virtualization technology.

Similar Papers
  • Conference Article
  • Citations1

Combining spark and snort technologies for detection of network attacks and anomalies

  • Sep 12, 2019
  • Igor Kotenko +1
  • Research Article
  • Citations72

Understanding Software-2.0

  • Jul 23, 2021
  • ACM Transactions on Software Engineering and Methodology
  • Malinda Dilhara +2
  • Research Article

Abstract 4138355: Machine Learning for Prediction of All-Cause Mortality in Acute Coronary Syndrome

  • Nov 12, 2024
  • Circulation
  • Aashray Gupta +18
  • Abstract

Using AI to Predict Patient's Atypical Prescription Based on Individual's Feature-Set

  • Oct 22, 2021
  • International Journal of Radiation Oncology*Biology*Physics
  • Q Li +2
  • Research Article
  • Citations5

The application of machine learning approaches to classify and predict fertility rate in Ethiopia

  • Jan 20, 2025
  • Scientific Reports
  • Ewunate Assaye Kassaw +3
  • Research Article

PUMAA: Establishing a protocol for utilizing machine learning in forensic anthropological analyses.

  • Feb 11, 2026
  • Journal of forensic sciences
  • Eman Faisal +1
  • Conference Article

Research of Detection Method of Server Network Storm Attack

  • Jan 01, 2015
  • Liao Lang
  • Research Article
  • Citations7

Exploration of Black Boxes of Supervised Machine Learning Models: A Demonstration on Development of Predictive Heart Risk Score.

  • May 12, 2022
  • Computational Intelligence and Neuroscience
  • Mirza Rizwan Sajid +6
  • Research Article
  • Citations1

Data-driven exploration of Na–Bi compounds: a first-principles and machine learning approach to topological thermoelectrics

  • Jan 01, 2025
  • RSC Advances
  • Souraya Goumri-Said +4
  • Research Article

Enhanced Language Models for Predicting and Understanding HIV Care Disengagement: A Case Study in Tanzania

  • May 08, 2025
  • Research Square
  • Waverly Wei +16
  • Research Article
  • Citations8

Security in 6G-Based Autonomous Vehicular Networks: Detecting Network Anomalies With Decentralized Federated Learning

  • Mar 01, 2025
  • IEEE Vehicular Technology Magazine
  • Jiazhen Zhang +3
  • PDF
  • Research Article
  • Citations9

Calibrating Wrist-Worn Accelerometers for Physical Activity Assessment in Preschoolers: Machine Learning Approaches

  • Aug 31, 2020
  • JMIR Formative Research
  • Shiyu Li +5
  • Research Article
  • Citations5

Physical Activity, Sedentary Behavior, and Sleep on Twitter: Multicountry and Fully Labeled Public Data Set for Digital Public Health Surveillance Research.

  • Feb 14, 2022
  • JMIR Public Health and Surveillance
  • Zahra Shakeri Hossein Abad +3
  • Research Article

The Role of Computer Deception in Network Security

  • Mar 03, 2025
  • Computer Fraud and Security
  • Zhuqiang Ye, Zexin Liu
  • Research Article

Development of machine learning models to predict risk of hospitalisation and 90-day readmission among patients with cardiovascular risk factors using community health survey data

  • Dec 31, 2025
  • BMJ Health & Care Informatics
  • Arinze Nkemdirim Okere +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.