Distributed Anomaly Detection in Edge Streams using Frequency based Sketch Datastructures

11/27/2021
by   Prateek Chanda, et al.
0

Often logs hosted in large data centers represent network traffic data over a long period of time. For instance, such network traffic data logged via a TCP dump packet sniffer (as considered in the 1998 DARPA intrusion attack) included network packets being transmitted between computers. While an online framework is necessary for detecting any anomalous or suspicious network activities like denial of service attacks or unauthorized usage in real time, often such large data centers log data over long periods of time (e.g., TCP dump) and hence an offline framework is much more suitable in such scenarios. Given a network log history of edges from a dynamic graph, how can we assign anomaly scores to individual edges indicating suspicious events with high accuracy using only constant memory and within limited time than state-of-the-art methods? We propose MDistrib and its variants which provides (a) faster detection of anomalous events via distributed processing with GPU support compared to other approaches, (b) better false positive guarantees than state of the art methods considering fixed space and (c) with collision aware based anomaly scoring for better accuracy results than state-of-the-art approaches. We describe experiments confirming that MDistrib is more efficient than prior work.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/11/2019

MIDAS: Microcluster-Based Detector of Anomalies in Edge Streams

Given a stream of graph edges from a dynamic graph, how can we assign an...
research
09/17/2020

Real-Time Streaming Anomaly Detection in Dynamic Graphs

Given a stream of graph edges from a dynamic graph, how can we assign an...
research
06/08/2021

Sketch-Based Streaming Anomaly Detection in Dynamic Graphs

Given a stream of graph edges from a dynamic graph, how can we assign an...
research
07/05/2023

Information-Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection and Prevention

Data exfiltration over the DNS protocol and its detection have been rese...
research
01/30/2023

Streaming Anomaly Detection

Anomaly detection is critical for finding suspicious behavior in innumer...
research
04/25/2020

Real-Time Anomaly Detection in Data Centers for Log-based Predictive Maintenance using an Evolving Fuzzy-Rule-Based Approach

Detection of anomalous behaviors in data centers is crucial to predictiv...
research
09/27/2021

Anomalous Edge Detection in Edge Exchangeable Social Network Models

This paper studies detecting anomalous edges in directed graphs that mod...

Please sign up or login with your details

Forgot password? Click here to reset