We introduce a real-time, node-based anomaly detection algorithm that observes the arrival processes experienced by a sensor node. Sensor nodes are resource constrained from many aspects. However they have specific properties such as lack of mobility and relatively predictable traffic patterns that allows for detection of anomalies in their networking behavior We develop a new arrival model for the traffic that can be received by a sensor node and devise a scheme to detect anomalous changes in this arrival process. Our detection algorithm keeps short-term dynamic statistics using a multi-level, sliding window event storage scheme. In this algorithm, arrival processes at different time scales are compared using node resourcewise computable, low-complexity, aggregate features.
Published in:
Systems Communications, 2005. Proceedings
Date of Conference: 14-17 Aug. 2005