MStream: Fast Streaming Multi-Aspect Group Anomaly Detection

09/17/2020
by   Siddharth Bhatia, et al.
18

Given a stream of entries in a multi-aspect data setting i.e., entries having multiple dimensions, how can we detect anomalous activities? For example, in the intrusion detection setting, existing work seeks to detect anomalous events or edges in dynamic graph streams, but this does not allow us to take into account additional attributes of each entry. Our work aims to define a streaming multi-aspect data anomaly detection framework, termed MStream, which can detect unusual group anomalies as they occur, in a dynamic manner. MStream has the following properties: (a) it detects anomalies in multi-aspect data including both categorical and numeric attributes; (b) it is online, thus processing each record in constant time and constant memory; (c) it can capture the correlation between multiple aspects of the data. MStream is evaluated over the KDDCUP99, CICIDS-DoS, UNSW-NB 15 and CICIDS-DDoS datasets, and outperforms state-of-the-art baselines.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/07/2021

MemStream: Memory-Based Anomaly Detection in Multi-Aspect Streams with Concept Drift

Given a stream of entries over time in a multi-aspect data setting where...
research
03/07/2023

Fast and Multi-aspect Mining of Complex Time-stamped Event Streams

Given a huge, online stream of time-evolving events with multiple attrib...
research
04/29/2022

HashNWalk: Hash and Random Walk Based Anomaly Detection in Hyperedge Streams

Sequences of group interactions, such as emails, online discussions, and...
research
01/30/2023

Streaming Anomaly Detection

Anomaly detection is critical for finding suspicious behavior in innumer...
research
06/08/2021

Sketch-Based Streaming Anomaly Detection in Dynamic Graphs

Given a stream of graph edges from a dynamic graph, how can we assign an...
research
11/26/2020

Fast and Accurate Anomaly Detection in Dynamic Graphs with a Two-Pronged Approach

Given a dynamic graph stream, how can we detect the sudden appearance of...
research
11/11/2019

MIDAS: Microcluster-Based Detector of Anomalies in Edge Streams

Given a stream of graph edges from a dynamic graph, how can we assign an...

Please sign up or login with your details

Forgot password? Click here to reset