Skip to main navigation Skip to search Skip to main content

Multi-Perspective Content Delivery Networks Security Framework Using Optimized Unsupervised Anomaly Detection

  • Li Yang*
  • , Abdallah Moubayed
  • , Abdallah Shami
  • , Parisa Heidari
  • , Amine Boukhtouta
  • , Adel Larabi
  • , Richard Brunner
  • , Stere Preda
  • , Daniel Migault
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

35 Scopus citations

Abstract

Content delivery networks (CDNs) provide efficient content distribution over the Internet. CDNs improve the connectivity and efficiency of global communications, but their caching mechanisms may be breached by cyber-attackers. Among the security mechanisms, effective anomaly detection forms an important part of CDN security enhancement. In this work, we propose a multi-perspective unsupervised learning framework for anomaly detection in CDNs. In the proposed framework, a multi-perspective feature engineering approach, an optimized unsupervised anomaly detection model that utilizes an isolation forest and a Gaussian mixture model, and a multi-perspective validation method, are developed to detect abnormal behaviors in CDNs mainly from the client Internet Protocol (IP) and node perspectives, therefore to identify the denial of service (DoS) and cache pollution attack (CPA) patterns. Experimental results are presented based on the analytics of eight days of real-world CDN log data provided by a major CDN operator. Through experiments, the abnormal contents, compromised nodes, malicious IPs, as well as their corresponding attack types, are identified effectively by the proposed framework and validated by multiple cybersecurity experts. This shows the effectiveness of the proposed method when applied to real-world CDN data.

Original languageEnglish
Pages (from-to)686-705
Number of pages20
JournalIEEE Transactions on Network and Service Management
Volume19
Issue number1
DOIs
StatePublished - 1 Mar 2022
Externally publishedYes

Bibliographical note

Publisher Copyright:
© 2022 IEEE.

Keywords

  • Bayesian optimization
  • Cache pollution attacks
  • DoS attacks
  • Gaussian mixture model
  • anomaly detection
  • content delivery networks

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Multi-Perspective Content Delivery Networks Security Framework Using Optimized Unsupervised Anomaly Detection'. Together they form a unique fingerprint.

Cite this