Time-Window Group-Correlation Support vs. Individual Features: A Detection of Abnormal Users

12/27/2020
by   Lun-Pin Yuan, et al.
4

Autoencoder-based anomaly detection methods have been used in identifying anomalous users from large-scale enterprise logs with the assumption that adversarial activities do not follow past habitual patterns. Most existing approaches typically build models by reconstructing single-day and individual-user behaviors. However, without capturing long-term signals and group-correlation signals, the models cannot identify low-signal yet long-lasting threats, and will wrongly report many normal users as anomalies on busy days, which, in turn, lead to high false positive rate. In this paper, we propose ACOBE, an Anomaly detection method based on COmpound BEhavior, which takes into consideration long-term patterns and group behaviors. ACOBE leverages a novel behavior representation and an ensemble of deep autoencoders and produces an ordered investigation list. Our evaluation shows that ACOBE outperforms prior work by a large margin in terms of precision and recall, and our case study demonstrates that ACOBE is applicable in practice for cyberattack detection.

READ FULL TEXT

page 4

page 6

page 8

page 10

research
05/20/2022

Anomaly Detection for Multivariate Time Series on Large-scale Fluid Handling Plant Using Two-stage Autoencoder

This paper focuses on anomaly detection for multivariate time series dat...
research
05/29/2019

Bayesian Anomaly Detection Using Extreme Value Theory

Data-driven anomaly detection methods typically build a model for the no...
research
07/02/2021

A Collective Anomaly Detection Method Over Bitcoin Network

The popularity and amazing attractiveness of cryptocurrencies, and espec...
research
02/02/2016

GraphPrints: Towards a Graph Analytic Method for Network Anomaly Detection

This paper introduces a novel graph-analytic approach for detecting anom...
research
09/06/2023

Reasonable Anomaly Detection in Long Sequences

Video anomaly detection is a challenging task due to the lack in approac...
research
02/26/2020

Wavelet-based Temporal Forecasting Models of Human Activities for Anomaly Detection

This paper presents a novel approach for temporal modelling of long-term...
research
02/26/2022

Regional-Local Adversarially Learned One-Class Classifier Anomalous Sound Detection in Global Long-Term Space

Anomalous sound detection (ASD) is one of the most significant tasks of ...

Please sign up or login with your details

Forgot password? Click here to reset