An empirical study of two approaches to sequence learning for anomaly detection

被引:70
|
作者
Lane, T [1 ]
Brodley, CE
机构
[1] Univ New Mexico, Dept Comp Sci, Albuquerque, NM 87131 USA
[2] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
关键词
anomaly detection; application; instance-based learning; hidden Markov models; computer security;
D O I
10.1023/A:1021830128811
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper introduces the computer security domain of anomaly detection and formulates it as a machine learning task on temporal sequence data. In this domain, the goal is to develop a model or profile of the normal working state of a system user and to detect anomalous conditions as long-term deviations from the expected behavior patterns. We introduce two approaches to this problem: one employing instance-based learning (IBL) and the other using hidden Markov models (HMMs). Though not suitable for a comprehensive security solution, both approaches achieve anomaly identification performance sufficient for a low-level "focus of attention" detector in a multitier security system. Further, we evaluate model scaling techniques for the two approaches: two clustering techniques for the IBL approach and variation of the number of hidden states for the HMM approach. We find that over both model classes and a wide range of model scales, there is no significant difference in performance at recognizing the profiled user. We take this invariance as evidence that, in this security domain, limited memory models (e.g., fixed-length instances or low-order Markov models) can learn only part of the user identity information in which we're interested and that substantially different models will be necessary if dramatic improvements in user-based anomaly detection are to be achieved.
引用
收藏
页码:73 / 107
页数:35
相关论文
共 50 条
  • [31] Machine Learning Approaches for Anomaly Detection in IoT: An Overview and Future Research Directions
    Alghanmi, Nusaybah
    Alotaibi, Reem
    Buhari, Seyed M.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 122 (03) : 2309 - 2324
  • [32] Machine Learning Approaches for Anomaly Detection in IoT: An Overview and Future Research Directions
    Nusaybah Alghanmi
    Reem Alotaibi
    Seyed M. Buhari
    Wireless Personal Communications, 2022, 122 : 2309 - 2324
  • [33] Anomaly Detection using Machine Learning with a Case Study
    Jidiga, Goverdhan Reddy
    Sammulal, P.
    2014 INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION CONTROL AND COMPUTING TECHNOLOGIES (ICACCCT), 2014, : 1060 - 1065
  • [34] KfreqGAN: Unsupervised detection of sequence anomaly with adversarial learning and frequency domain information
    Yao, Yueyue
    Ma, Jianghong
    Ye, Yunming
    Knowledge-Based Systems, 2022, 236
  • [35] KfreqGAN: Unsupervised detection of sequence anomaly with adversarial learning and frequency domain information
    Yao, Yueyue
    Ma, Jianghong
    Ye, Yunming
    KNOWLEDGE-BASED SYSTEMS, 2022, 236
  • [36] Anomaly Detection of Orbit Satellite Telemetry Sequence Based on Two -Window Mode
    Ying, Du
    Fei, Wang
    Chao, Sun
    Jie, Bao
    Qi, Yang
    PROCEEDINGS OF THE 30TH CHINESE CONTROL AND DECISION CONFERENCE (2018 CCDC), 2018, : 1064 - 1068
  • [37] Two state-based approaches to program-based anomaly detection
    Michael, CC
    Ghosh, A
    16TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2000, : 21 - 30
  • [38] An Empirical Study on Network Anomaly Detection using Convolutional Neural Networks
    Kwon, Donghwoon
    Natarajan, Kathiravan
    Suh, Sang C.
    Kim, Hyunjoo
    Kim, Jinoh
    2018 IEEE 38TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2018, : 1595 - 1598
  • [39] Learning to cluster urban areas: two competitive approaches and an empirical validation
    Camila Vera
    Francesca Lucchini
    Naim Bro
    Marcelo Mendoza
    Hans Löbel
    Felipe Gutiérrez
    Jan Dimter
    Gabriel Cuchacovic
    Axel Reyes
    Hernán Valdivieso
    Nicolás Alvarado
    Sergio Toro
    EPJ Data Science, 11
  • [40] Learning to cluster urban areas: two competitive approaches and an empirical validation
    Vera, Camila
    Lucchini, Francesca
    Bro, Naim
    Mendoza, Marcelo
    Loebel, Hans
    Gutierrez, Felipe
    Dimter, Jan
    Cuchacovic, Gabriel
    Reyes, Axel
    Valdivieso, Hernan
    Alvarado, Nicolas
    Toro, Sergio
    EPJ DATA SCIENCE, 2022, 11 (01)