An empirical study of two approaches to sequence learning for anomaly detection

被引:70
|
作者
Lane, T [1 ]
Brodley, CE
机构
[1] Univ New Mexico, Dept Comp Sci, Albuquerque, NM 87131 USA
[2] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
关键词
anomaly detection; application; instance-based learning; hidden Markov models; computer security;
D O I
10.1023/A:1021830128811
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper introduces the computer security domain of anomaly detection and formulates it as a machine learning task on temporal sequence data. In this domain, the goal is to develop a model or profile of the normal working state of a system user and to detect anomalous conditions as long-term deviations from the expected behavior patterns. We introduce two approaches to this problem: one employing instance-based learning (IBL) and the other using hidden Markov models (HMMs). Though not suitable for a comprehensive security solution, both approaches achieve anomaly identification performance sufficient for a low-level "focus of attention" detector in a multitier security system. Further, we evaluate model scaling techniques for the two approaches: two clustering techniques for the IBL approach and variation of the number of hidden states for the HMM approach. We find that over both model classes and a wide range of model scales, there is no significant difference in performance at recognizing the profiled user. We take this invariance as evidence that, in this security domain, limited memory models (e.g., fixed-length instances or low-order Markov models) can learn only part of the user identity information in which we're interested and that substantially different models will be necessary if dramatic improvements in user-based anomaly detection are to be achieved.
引用
收藏
页码:73 / 107
页数:35
相关论文
共 50 条
  • [21] Anomaly detection in discrete manufacturing using self-learning approaches
    Lindemann, Benjamin
    Fesenmayr, Fabian
    Jazdi, Nasser
    Weyrich, Michael
    12TH CIRP CONFERENCE ON INTELLIGENT COMPUTATION IN MANUFACTURING ENGINEERING, 2019, 79 : 313 - 318
  • [22] Review on Deep Learning Approaches for Anomaly Event Detection in Video Surveillance
    Jebur, Sabah Abdulazeez
    Hussein, Khalid A.
    Hoomod, Haider Kadhim
    Alzubaidi, Laith
    Santamaria, Jose
    ELECTRONICS, 2023, 12 (01)
  • [23] Enhancing Critical Infrastructure Security: Unsupervised Learning Approaches for Anomaly Detection
    Pinto, Andrea
    Herrera, Luis-Carlos
    Donoso, Yezid
    Gutierrez, Jairo A.
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2024, 17 (01)
  • [24] An Empirical Study on Anomaly Detection Algorithms for Extremely Imbalanced Datasets
    Fontes, Goncalo
    Matos, Luis Miguel
    Matta, Arthur
    Pilastri, Andre
    Cortez, Paulo
    ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS, AIAI 2022, PART I, 2022, 646 : 85 - 95
  • [25] Empirical Comparison of Approaches for Mitigating Effects of Class Imbalances in Water Quality Anomaly Detection
    Dogo, Eustace M.
    Nwulu, Nnamdi I.
    Twala, Bhekisipho
    Aigbavboa, Clinton Ohis
    IEEE ACCESS, 2020, 8 : 218015 - 218036
  • [26] Sequence to Sequence Pattern Learning Algorithm for Real-time Anomaly Detection in Network Traffic
    Loganathan, Gobinath
    Samarabandu, Jagath
    Wang, Xianbin
    2018 IEEE CANADIAN CONFERENCE ON ELECTRICAL & COMPUTER ENGINEERING (CCECE), 2018,
  • [27] AIoT-Based Visual Anomaly Detection in Photovoltaic Sequence Data via Sequence Learning
    Wei, Qian
    Sun, Hongjun
    Fan, Jingjing
    Li, Guojun
    Zhou, Zhiguang
    ENERGIES, 2024, 17 (21)
  • [28] An Empirical Study of Learning Based Happiness Prediction Approaches
    Miao Kong
    Lin Li
    Renwei Wu
    Xiaohui Tao
    Human-Centric Intelligent Systems, 2021, 1 (1-2): : 18 - 24
  • [29] Deep learning for anomaly detection in multivariate time series: Approaches, applications, and challenges
    Li, Gen
    Jung, Jason J.
    INFORMATION FUSION, 2023, 91 : 93 - 102
  • [30] WoodAD: A New Dataset and a Comparison of Deep Learning Approaches for Wood Anomaly Detection
    del-Tejo-Catala, Omar
    Perez, Javier
    Garcia, Nicolas
    Perez-Cortes, Juan-Carlos
    Del Ser, Javier
    EXPERT SYSTEMS, 2025, 42 (03)