Anomaly Detection in Large-Scale Networks With Latent Space Models

被引:8
|
作者
Lee, Wesley [1 ]
McCormick, Tyler H. [1 ,2 ]
Neil, Joshua [3 ]
Sodja, Cole [3 ]
Cui, Yanran [1 ]
机构
[1] Univ Washington, Dept Stat, Seattle, WA 98195 USA
[2] Univ Washington, Dept Sociol, Seattle, WA 98195 USA
[3] Microsoft, Redmond, WA USA
关键词
Anomaly detection; Networks; Scaleable computing; INFERENCE;
D O I
10.1080/00401706.2021.1952900
中图分类号
O21 [概率论与数理统计]; C8 [统计学];
学科分类号
020208 ; 070103 ; 0714 ;
摘要
We develop a real-time anomaly detection method for directed activity on large, sparse networks. We model the propensity for future activity using a dynamic logistic model with interaction terms for sender- and receiver-specific latent factors in addition to sender- and receiver-specific popularity scores; deviations from this underlying model constitute potential anomalies. Latent nodal attributes are estimated via a variational Bayesian approach and may change over time, representing natural shifts in network activity. Estimation is augmented with a case-control approximation to take advantage of the sparsity of the network and reduces computational complexity from O(N-2) to O(E), where N is the number of nodes and E is the number of observed edges. We run our algorithm on network event records collected from an enterprise network of over 25,000 computers and are able to identify a red team attack with half the detection rate required of the model without latent interaction terms.
引用
收藏
页码:241 / 252
页数:12
相关论文
共 50 条
  • [31] On The Detection of DDoS Attackers for Large-Scale Networks
    Nashat, Dalia
    Jiang, Xiaohong
    Horiguchi, Susumu
    [J]. ICEBE 2009: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2009, : 206 - 212
  • [32] DongTing: A large-scale dataset for anomaly detection of the Linux kernel
    Duan, Guoyun
    Fu, Yuanzhi
    Cai, Minjie
    Chen, Hao
    Sun, Jianhua
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2023, 203
  • [33] Connecting the dots: anomaly and discontinuity detection in large-scale systems
    Haroon Malik
    Ian J. Davis
    Michael W. Godfrey
    Douglas Neuse
    Serge Manskovskii
    [J]. Journal of Ambient Intelligence and Humanized Computing, 2016, 7 : 509 - 522
  • [34] Detection of Instability for Civil Large-Scale Space Structures
    Carrasco, C.
    Fang, C.
    Feng, R.
    Yan, G.
    [J]. STRUCTURAL HEALTH MONITORING 2013, VOLS 1 AND 2, 2013, : 96 - +
  • [35] Fluid models for large-scale wireless sensor networks
    Chiasserini, C.-F.
    Gaeta, R.
    Garetto, M.
    Gribaudo, M.
    Manini, D.
    Sereno, M.
    [J]. PERFORMANCE EVALUATION, 2007, 64 (7-8) : 715 - 736
  • [36] MODELS OF COMMUNICATION NETWORKS IN LARGE-SCALE SYSTEMS.
    Gasalino, G.
    Davoli, F.
    Puliafito, P.P.
    Zoppoli, R.
    [J]. Ricerche di Automatica, 1976, 7 (01): : 60 - 91
  • [37] Generating Null Models for Large-Scale Networks on GPU
    Li, Huan
    Lu, Gang
    Guo, Junxia
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL INDUSTRIAL INFORMATICS AND COMPUTER ENGINEERING CONFERENCE, 2015, : 204 - 208
  • [38] Constant Time EXPected Similarity Estimation for Large-Scale Anomaly Detection
    Schneider, Markus
    Ertel, Wolfgang
    Palm, Guenther
    [J]. ECAI 2016: 22ND EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2016, 285 : 12 - 20
  • [39] Expected similarity estimation for large-scale batch and streaming anomaly detection
    Schneider, Markus
    Ertel, Wolfgang
    Ramos, Fabio
    [J]. MACHINE LEARNING, 2016, 105 (03) : 305 - 333
  • [40] Efficient and Robust Trace Anomaly Detection for Large-Scale Microservice Systems
    Zhang, Shenglin
    Pan, Zhongjie
    Liu, Heng
    Jin, Pengxiang
    Sun, Yongqian
    Ouyang, Qianyu
    Wang, Jiaju
    Jia, Xueying
    Zhang, Yuzhi
    Yang, Hui
    Zou, Yongqiang
    Pei, Dan
    [J]. 2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, ISSRE, 2023, : 69 - 79