pith. sign in

arxiv: 1503.02332 · v1 · pith:IK3RLMFLnew · submitted 2015-03-08 · 💻 cs.NI · stat.AP

Robust Anomaly Detection in Dynamic Networks

classification 💻 cs.NI stat.AP
keywords methodsrobustanomalynormaldetectiondynamicnetworkstraffic
0
0 comments X
read the original abstract

We propose two robust methods for anomaly detection in dynamic networks in which the properties of normal traffic are time-varying. We formulate the robust anomaly detection problem as a binary composite hypothesis testing problem and propose two methods: a model-free and a model-based one, leveraging techniques from the theory of large deviations. Both methods require a family of Probability Laws (PLs) that represent normal properties of traffic. We devise a two-step procedure to estimate this family of PLs. We compare the performance of our robust methods and their vanilla counterparts, which assume that normal traffic is stationary, on a network with a diurnal normal pattern and a common anomaly related to data exfiltration. Simulation results show that our robust methods perform better than their vanilla counterparts in dynamic networks.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.