DenDrift: A Drift-Aware Algorithm for Host Profiling

10/04/2021
by   Ali Sedaghatbaf, et al.
0

Detecting and reacting to unauthorized actions is an essential task in security monitoring. What make this task challenging are the large number and various categories of hosts and processes to monitor. To these we should add the lack of an exact definition of normal behavior for each category. Host profiling using stream clustering algorithms is an effective means of analyzing hosts' behaviors, categorizing them, and identifying atypical ones. However, unforeseen changes in behavioral data (i.e. concept drift) make the obtained profiles unreliable. DenStream is a well-known stream clustering algorithm, which can be effectively used for host profiling. This algorithm is an incremental extension of DBSCAN which is a non-parametric algorithm widely used in real-world clustering applications. Recent experimental studies indicate that DenStream is not robust against concept drift. In this paper, we present DenDrift as a drift-aware host profiling algorithm based on DenStream. DenDrift relies on non-negative matrix factorization for dimensionality reduction and Page-Hinckley test for drift detection. We have done experiments on both synthetic and industrial datasets and the results affirm the robustness of DenDrift against abrupt, gradual and incremental drifts.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/16/2022

Class Distribution Monitoring for Concept Drift Detection

We introduce Class Distribution Monitoring (CDM), an effective concept-d...
research
03/30/2020

A Novel Incremental Clustering Technique with Concept Drift Detection

Data are being collected from various aspects of life. These data can of...
research
09/16/2021

Soft Confusion Matrix Classifier for Stream Classification

In this paper, the issue of tailoring the soft confusion matrix (SCM) ba...
research
04/24/2020

Concept Drift Detection via Equal Intensity k-means Space Partitioning

Data stream poses additional challenges to statistical classification ta...
research
09/17/2023

Detecting covariate drift in text data using document embeddings and dimensionality reduction

Detecting covariate drift in text data is essential for maintaining the ...
research
12/25/2012

Exponentially Weighted Moving Average Charts for Detecting Concept Drift

Classifying streaming data requires the development of methods which are...
research
06/24/2020

Ensuring Learning Guarantees on Concept Drift Detection with Statistical Learning Theory

Concept Drift (CD) detection intends to continuously identify changes in...

Please sign up or login with your details

Forgot password? Click here to reset