Network-wide anomaly detection via the Dirichlet process

Network-wide anomaly detection via the Dirichlet process
复制标题

通过狄利克雷过程进行全网异常检测

DOI:
--
复制
发表时间:
2016
期刊:
Intelligence and Security Informatics
影响因子:
--
通讯作者:
Patrick Rubin
Patrick Rubin
中科院分区:
--
文献类型:
--
作者:
N. Heard;Patrick Rubin

文献摘要

被引文献

相似文献

统计异常检测技术在基于传统的基于签名的方法下提供了下一层的网络安全防御能力。本文提出了一种可扩展的,原则的,基于概率的技术,用于检测有向交互网络(例如计算机网络)中的外围连接行为。独立的贝叶斯统计模型使用Dirichlet过程适合网络中的每个消息接收者,该过程为未知的离散概率分布提供了可拖动的,共轭的先验分布。该方法显示出在从洛斯阿拉莫斯国家实验室的企业网络获得的身份验证数据中成功检测到的红色团队攻击。
Statistical anomaly detection techniques provide the next layer of cyber-security defences below traditional signature-based approaches. This article presents a scalable, principled, probability-based technique for detecting outlying connectivity behaviour within a directed interaction network such as a computer network. Independent Bayesian statistical models are fit to each message recipient in the network using the Dirichlet process, which provides a tractable, conjugate prior distribution for an unknown discrete probability distribution. The method is shown to successfully detect a red team attack in authentication data obtained from the enterprise network of Los Alamos National Laboratory.