Network anomaly detection based on tensor decomposition

Network anomaly detection based on tensor decomposition
复制标题

基于张量分解的网络异常检测

DOI:
10.1016/j.comnet.2021.108503
复制
发表时间:
2021
期刊:
影响因子:
5.6
通讯作者:
Towsley, Don
Towsley, Don
中科院分区:
计算机科学3区
文献类型:
--
作者:
Streit, Ananda;Santos, Gustavo H.A.;Leão, Rosa M.M.;de Souza e Silva, Edmundo;Menasché, Daniel;Towsley, Don

文献摘要

相似文献

从网络测量中检测时间序列中的异常已经得到了广泛的研究,这是一个具有重要意义的课题。许多异常检测方法都是基于对网络核心路由器上收集的分组进行检测的,因此在计算成本和保密性方面存在缺陷。我们提出了一种不需要分组报头检查的替代方法。该方法基于考虑度量之间相关性的张量分解技术得到的正规子空间的提取。在其在线版本中,所提出的张量分解方法允许有效地跟踪正常子空间中的变化。通过将该方法应用于包括监督和非监督异常检测在内的不同实例,说明了该方法的灵活性。这些示例使用在住宅路由器上收集的实际数据。
The problem of detecting anomalies in time series from network measurements has been widely studied and is a topic of fundamental importance. Many anomaly detection methods are based on the inspection of packets collected at the network core routers, with consequent disadvantages in terms of computational cost and privacy. We propose an alternative method in which packet header inspection is not needed. The method is based on the extraction of a normal subspace obtained by the tensor decomposition technique considering the correlation among metrics. In its online version, the proposed approach for tensor decomposition allows efficient tracking of changes in the normal subspace. The flexibility of the method is illustrated by applying it to distinct examples that include supervised and unsupervised anomaly detection. The examples use actual data collected at residential routers.