
10/23/2024 · Nick Wood, Manish Arora
What this post added
This post introduces an advanced anomaly detection pipeline for identifying novel and subtle DDoS attacks. It details the limitations of naive volumetric models and time series forecasting, then presents a more robust approach using multiple traffic characteristics (beyond volume) analyzed through Principal Component Analysis (PCA) and Mahalanobis distance. This enables the training of millions of models daily to detect attacks that might otherwise go unnoticed, particularly for smaller customers.