State Frequency Estimation for Anomaly Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cao, Clinton, Blaise, Agathe, Panichella, Annibale, Verwer, Sicco
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913726646452224
author Cao, Clinton
Blaise, Agathe
Panichella, Annibale
Verwer, Sicco
author_facet Cao, Clinton
Blaise, Agathe
Panichella, Annibale
Verwer, Sicco
contents Many works have studied the efficacy of state machines for detecting anomalies within NetFlows. These works typically learn a model from unlabeled data and compute anomaly scores for arbitrary traces based on their likelihood of occurrence or how well they fit within the model. However, these methods do not dynamically adapt their scores based on the traces seen at test time. This becomes a problem when an adversary produces seemingly common traces in their attack, causing the model to miss the detection by assigning low anomaly scores. We propose SEQUENT, a new unsupervised approach that uses the state visit frequency of a state machine to adapt its scoring dynamically for anomaly detection. SEQUENT subsequently uses the scores to generate root causes for anomalies. These allow the grouping of alarms and simplify the analysis of anomalies. We evaluate SEQUENT's effectiveness in detecting network anomalies on three publicly available NetFlow datasets and compare its performance against various existing unsupervised anomaly detection methods. Our evaluation shows promising results for using the state visit frequency of a state machine to detect network anomalies.
format Preprint
id arxiv_https___arxiv_org_abs_2412_03442
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle State Frequency Estimation for Anomaly Detection
Cao, Clinton
Blaise, Agathe
Panichella, Annibale
Verwer, Sicco
Machine Learning
Cryptography and Security
Many works have studied the efficacy of state machines for detecting anomalies within NetFlows. These works typically learn a model from unlabeled data and compute anomaly scores for arbitrary traces based on their likelihood of occurrence or how well they fit within the model. However, these methods do not dynamically adapt their scores based on the traces seen at test time. This becomes a problem when an adversary produces seemingly common traces in their attack, causing the model to miss the detection by assigning low anomaly scores. We propose SEQUENT, a new unsupervised approach that uses the state visit frequency of a state machine to adapt its scoring dynamically for anomaly detection. SEQUENT subsequently uses the scores to generate root causes for anomalies. These allow the grouping of alarms and simplify the analysis of anomalies. We evaluate SEQUENT's effectiveness in detecting network anomalies on three publicly available NetFlow datasets and compare its performance against various existing unsupervised anomaly detection methods. Our evaluation shows promising results for using the state visit frequency of a state machine to detect network anomalies.
title State Frequency Estimation for Anomaly Detection
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2412.03442