Knowledge-based anomaly detection: Survey, challenges, and future directions

被引:3
|
作者
Khan, Abdul Qadir [1 ,2 ]
El Jaouhari, Saad [1 ]
Tamani, Nouredine [1 ]
Mroueh, Lina [1 ]
机构
[1] Inst Super Elect Paris Isep, 10 rue Vanves, F-92130 Issy les moulineaux, France
[2] Sorbonne Univ, Paris, France
关键词
Anomaly detection; Knowledge base systems; Rule-based systems; Fuzzy logic; Machine learning; Survey; NETWORK INTRUSION DETECTION; FEATURE-SELECTION; DETECTION SYSTEMS; FUZZY-LOGIC; IDENTIFICATION; ACQUISITION; COMPLEXITY; ONTOLOGY; ATTACKS; DESIGN;
D O I
10.1016/j.engappai.2024.108996
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the rapidly increasing number of Internet-connected objects, a huge amount of data is created, stored, and shared. Depending on the use case, this data is visualized, cleaned, checked, visualized, and processed for various purposes. However, this data may encounter many problems such as inaccuracy, duplication, absence, etc. Such issues can be regarded as anomalies that deviate from a referential point, which can be caused by malicious attackers, abnormal behavior of systems, and a failure of devices, transmission channels, or data processing units. Anomaly detection is still one of the most important issues in cybersecurity, especially when it comes to system monitoring, automated forensics, and post-mortem analysis, which require anomaly detection mechanisms. In the literature, different approaches have been developed to detect anomalies, which can be classified as statistic-based, semantic-based, clustering-based, classification-based, and deep learning-based, depending on the algorithms used. This survey focuses on knowledge-based approaches, a sub-category of semantic-based approaches, as opposed to statistical/learning approaches. We provide a detailed comparison of the recent work in knowledge-based subcategories, namely, rule-based, score-based, and hybrid. We described the components of a knowledge-based system and the steps required to process raw data for anomaly detection. Furthermore, we have collected for each approach, when available, information about its semantic expressiveness, computational complexity, and application domain. Finally, we identify the challenges and discuss some future research directions in knowledge-based anomaly detection. Identifying such approaches and challenges can help cybersecurity engineers design better models that meet their application requirements.
引用
收藏
页数:21
相关论文
共 50 条
  • [41] Arabic Machine Translation: A Survey With Challenges and Future Directions
    Zakraoui, Jezia
    Saleh, Moutaz
    Al-Maadeed, Somaya
    Alja'am, Jihad Mohamed
    IEEE ACCESS, 2021, 9 : 161445 - 161468
  • [42] A survey on Ethereum pseudonymity: Techniques, challenges, and future directions
    Jamwal, Shivani
    Cano, Jose
    Lee, Gyu Myoung
    Tran, Nguyen H.
    Truong, Nguyen
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 232
  • [43] A Survey on Blockchain for Healthcare: Challenges, Benefits, and Future Directions
    Arbabi, Mohammad Salar
    Lal, Chhagan
    Veeraragavan, Narasimha Raghavan
    Marijan, Dusica
    Nygard, Jan F.
    Vitenberg, Roman
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2023, 25 (01): : 386 - 424
  • [44] Mobile Trajectory Anomaly Detection: Taxonomy, Methodology, Challenges, and Directions
    Kong, Xiangjie
    Wang, Juntao
    Hu, Zehao
    He, Yuwei
    Zhao, Xiangyu
    Shen, Guojiang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (11): : 19210 - 19231
  • [45] Knowledge cities: The future of cities in the knowledge-based economy
    Ergazakis, Kostas
    Metaxiotis, Kostas
    Ergazakis, Emmanouil
    Psarras, John
    2007 INNOVATIONS IN INFORMATION TECHNOLOGIES, VOLS 1 AND 2, 2007, : 397 - +
  • [46] Knowledge-based recommender systems: overview and research directions
    Uta, Mathias
    Felfernig, Alexander
    Le, Viet-Man
    Tran, Thi Ngoc Trang
    Garber, Damian
    Lubos, Sebastian
    Burgstaller, Tamim
    FRONTIERS IN BIG DATA, 2024, 7
  • [47] Knowledge-Based System for the Engineering of Automation Systems Potentials, Applications, Deficits and Future Challenges
    Runde, Stefan
    Fay, Alexander
    Schmitz, Stefan
    Epple, Ulrich
    AT-AUTOMATISIERUNGSTECHNIK, 2011, 59 (01) : 42 - 49
  • [48] Visions and open challenges for a knowledge-based culturomics
    Tahmasebi, Nina
    Borin, Lars
    Capannini, Gabriele
    Dubhashi, Devdatt
    Exner, Peter
    Forsberg, Markus
    Gossen, Gerhard
    Johansson, Fredrik D.
    Johansson, Richard
    Kageback, Mikael
    Mogren, Olof
    Nugues, Pierre
    Risse, Thomas
    INTERNATIONAL JOURNAL ON DIGITAL LIBRARIES, 2015, 15 (2-4) : 169 - 187
  • [49] Assessment for a Knowledge-Based Era - Issues and Challenges
    Idris, Noraini
    LINKING APPLICATIONS WITH MATHEMATICS AND TECHNOLOGY, 2010, : 30 - 36
  • [50] Blockchain-Based Data Breach Detection: Approaches, Challenges, and Future Directions
    Ansar, Kainat
    Ahmed, Mansoor
    Helfert, Markus
    Kim, Jungsuk
    MATHEMATICS, 2024, 12 (01)