Search papers, labs, and topics across Lattice.
This paper addresses the challenge of distinguishing between normal traffic patterns and volumetric attacks in Research and Education Networks (RENs) by introducing a high-fidelity traffic forecasting framework. Utilizing a unique 57-day dataset from Internet2, the authors benchmark six model families, revealing that advanced architectures like TiDE can reduce baseline prediction error by 30-42% compared to traditional methods. The study also presents a novel anomaly-integration strategy that enhances model robustness, ultimately providing a statistically validated approach for improving network security operations in RENs.
Advanced forecasting models can cut anomaly detection errors by up to 42%, transforming how we secure research networks against real threats.
Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty"elephant flows"are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems. This similarity leads to high false-positive rates in anomaly detection, blinding security operators to genuine threats. In this paper, we propose and evaluate a high-fidelity traffic forecasting framework designed to establish dynamic security baselines for RENs. Leveraging an exclusive 57-day Internet2 dataset spanning ten backbone routers (13.7 billion packets), we perform the first large-scale benchmark of anomaly-aware forecasting models in this domain. We systematically evaluate six model families, from SARIMA to state-of-the-art long-sequence architectures (TiDE, PatchTST), across 960 experimental configurations. Our results demonstrate that these advanced architectures, particularly TiDE, reduce baseline prediction error by 30-42% compared to traditional methods ($p<0.001$), significantly improving the distinction between legitimate scientific bursts and potential anomalies. Furthermore, we introduce a novel anomaly-integration strategy that improves model robustness by 3.3% in the presence of noise. This work provides the first statistically validated framework for distinguishing scientific workflows from network attacks, enabling more autonomous and resilient network security operations.