Entity Embedding-based Anomaly Detection for Heterogeneous Categorical Events

by   Ting Chen, et al.

Anomaly detection plays an important role in modern data-driven security applications, such as detecting suspicious access to a socket from a process. In many cases, such events can be described as a collection of categorical values that are considered as entities of different types, which we call heterogeneous categorical events. Due to the lack of intrinsic distance measures among entities, and the exponentially large event space, most existing work relies heavily on heuristics to calculate abnormal scores for events. Different from previous work, we propose a principled and unified probabilistic model APE (Anomaly detection via Probabilistic pairwise interaction and Entity embedding) that directly models the likelihood of events. In this model, we embed entities into a common latent space using their observed co-occurrence in different events. More specifically, we first model the compatibility of each pair of entities according to their embeddings. Then we utilize the weighted pairwise interactions of different entity types to define the event probability. Using Noise-Contrastive Estimation with "context-dependent" noise distribution, our model can be learned efficiently regardless of the large event space. Experimental results on real enterprise surveillance data show that our methods can accurately detect abnormal events compared to other state-of-the-art abnormal detection techniques.


page 1

page 2

page 3

page 4


Abnormal Event Detection via Hypergraph Contrastive Learning

Abnormal event detection, which refers to mining unusual interactions am...

Joint Detection and Recounting of Abnormal Events by Learning Deep Generic Knowledge

This paper addresses the problem of joint detection and recounting of ab...

GeoTrackNet-A Maritime Anomaly Detector using Probabilistic Neural Network Representation of AIS Tracks and A Contrario Detection

Representing maritime traffic patterns and detecting anomalies from them...

Internet Anomaly Detection based on Complex Network Path

Detecting the anomaly behaviors such as network failure or Internet inte...

Detecting Anomalies Through Contrast in Heterogeneous Data

Detecting anomalies has been a fundamental approach in detecting potenti...

BSSAD: Towards A Novel Bayesian State-Space Approach for Anomaly Detection in Multivariate Time Series

Detecting anomalies in multivariate time series(MTS) data plays an impor...

A Probabilistic Framework to Node-level Anomaly Detection in Communication Networks

In this paper we consider the task of detecting abnormal communication v...

Please sign up or login with your details

Forgot password? Click here to reset