Community-based anomaly detection

被引:0
|
作者
Kopp, Martin [1 ,2 ]
Grill, Martin [1 ]
Kohout, Jan [1 ,2 ]
机构
[1] Cisco Syst Inc, San Jose, CA 95134 USA
[2] Czech Tech Univ, Prague, Czech Republic
关键词
anomaly detection; behavioural clustering; malware detection;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Network behaviour anomaly detection systems can detect zero-day attacks and work even with encrypted traffic. They maintain a model of normal behaviour and report any deviation as anomaly. Typically, a separated model for each host is generated or there is one model for the whole network. The model of normal can be built for the whole network or for each network host separately. The per host models suffer from a small amount of noisy data as the behaviour of a single user is typically not very stable. The single model for the whole network is more robust to fluctuations, but it is trying to find a normal behaviour of a group of hosts with possibly diverse behaviour. We propose a method for clustering network hosts based on their network behaviour to create groups of hosts that behave similarly. The anomaly detection models trained on such groups of network hosts are more robust to fluctuations of the behaviour of individual hosts when compared to the per host models. It is able to detect finer anomalies (e.g. stealthy data ex-filtration) that would be otherwise hidden by modelling diversely behaving network hosts together.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Community anomaly detection in attribute networks based on refining context
    Lin, Yonghui
    Xu, Li
    Lin, Wei
    Li, Jiayin
    COMPUTING, 2024, 106 (06) : 1987 - 2006
  • [22] Attribution-based anomaly detection: Trustworthiness in an online community
    Ho, Shuyuan Mary
    SOCIAL COMPUTING, BEHAVIORAL MODELING AND PREDICTION, 2008, : 129 - 140
  • [23] Community-based provision of statin and aspirin after the detection of coronary artery calcium within a community-based screening cohort
    Taylor, Allen J.
    Bindeman, Jody
    Feuerstein, Irwin
    Le, Toan
    Bauer, Kelly
    Byrd, Carole
    Wu, Holly
    O'Malley, Patrick G.
    JOURNAL OF THE AMERICAN COLLEGE OF CARDIOLOGY, 2008, 51 (14) : 1337 - 1341
  • [24] Early detection of dementia in the community under a community-based integrated care system
    Maki, Yohko
    Yamaguchi, Haruyasu
    GERIATRICS & GERONTOLOGY INTERNATIONAL, 2014, 14 : 2 - 10
  • [25] Community-based cheater detection in location-based social networks
    Fan, Wenjie
    Fan, Wei
    Liao, Stephen Shayi
    Yeung, Kai-Hau
    2014 PROCEEDINGS OF THE IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM 2014), 2014, : 936 - 941
  • [26] A Community-Based Intervention for the Detection of Chagas Disease in Barcelona, Spain
    Gomez i Prat, Jordi
    Peremiquel-Trillas, Paula
    Claveria Guiu, Isabel
    Choque, Estefa
    Oliveira Souto, Ines
    Serre Delcor, Nuria
    Sulleiro, Elena
    Espasa, Mateu
    Pastoret, Conxita
    Jose de los Santos, Juan
    Ouaarab, Hakima
    Vinas, Pedro Albajar
    Ascaso Terren, Carlos
    JOURNAL OF COMMUNITY HEALTH, 2019, 44 (04) : 704 - 711
  • [27] A Community-Based Intervention for the Detection of Chagas Disease in Barcelona, Spain
    Jordi Gómez i Prat
    Paula Peremiquel-Trillas
    Isabel Claveria Guiu
    Estefa Choque
    Inés Oliveira Souto
    Núria Serre Delcor
    Elena Sulleiro
    Mateu Espasa
    Conxita Pastoret
    Juan José de los Santos
    Hakima Ouaarab
    Pedro Albajar Viñas
    Carlos Ascaso Terren
    Journal of Community Health, 2019, 44 : 704 - 711
  • [28] Detection of Memory Impairment in a Community-Based System: A Collaborative Study
    Kiral, Kahraman
    Ozge, Aynur
    Sungur, Mehmet Ali
    Tasdelen, Bahar
    HEALTH & SOCIAL WORK, 2013, 38 (02) : 89 - 96
  • [29] Anomaly, reciprocity, and community detection in networks
    Safdari, Hadiseh
    Contisciani, Martina
    De Bacco, Caterina
    PHYSICAL REVIEW RESEARCH, 2023, 5 (03):
  • [30] A Framework for Event Anomaly Detection in Cognitive Radio Based Smart Community
    Uddin, S. M. Nadim
    Mansoor, Nafees
    Rahman, Musfiqur
    Mohammed, Nabeel
    Hossain, Sazzad
    2016 INTERNATIONAL WORKSHOP ON COMPUTATIONAL INTELLIGENCE (IWCI), 2016, : 148 - 152