A scalable Bayesian framework for large-scale sensor-driven network anomaly detection

A scalable Bayesian framework for large-scale sensor-driven network anomaly detection
复制标题

DOI:
10.1080/24725854.2022.2037792
复制
发表时间:
2022-04
期刊:
影响因子:
2.6
通讯作者:
Feiran Xu;R. Moghaddass
Feiran Xu;R. Moghaddass
中科院分区:
工程技术3区
文献类型:
--
作者:
Feiran Xu;R. Moghaddass

文献摘要

相似文献

摘要许多真实的系统具有网络/图结构,其中有许多连接的节点和许多表示节点之间的确定性或随机依赖性和相互作用的边。随着时间的推移,各种类型的已知或未知的异常和干扰可能会发生在这些网络上。开发实时异常检测和隔离框架对于使网络运营商能够做出更明智和及时的决策并采取适当的维护和运营行动至关重要。为了真实的监控现代网络的健康状况,在这些网络上安装了不同类型的传感器和智能设备,可以跟踪来自特定节点或网络部分的实时数据。在这篇文章中,我们介绍了一种创新的推理方法来计算一组隐藏的节点在异构属性网络与贝叶斯网络表示的有向无环图结构的最可能的解释,给定的值的一组二进制数据从可用的传感器,这可能只位于一个子集的节点。贝叶斯网络的创新使用,将并行化和向量化,使所提出的框架适用于大规模的图形结构。通过一组全面的数值实验表明,该模型的效率。
Abstract Many real systems have a network/graph structure with many connected nodes and many edges representing deterministic or stochastic dependencies and interactions between nodes. Various types of known or unknown anomalies and disturbances may occur across these networks over time. Developing real-time anomaly detection and isolation frameworks is crucial to enable network operators to make more informed and timely decisions and take appropriate maintenance and operations actions. To monitor the health of modern networks in real time, different types of sensors and smart devices are installed across these networks that can track real-time data from a particular node or a section of a network. In this article, we introduce an innovative inference method to calculate the most probable explanation of a set of hidden nodes in heterogeneous attributed networks with a directed acyclic graph structure represented by a Bayesian network, given the values of a set of binary data observed from available sensors, which may be located only at a subset of nodes. The innovative use of Bayesian networks to incorporate parallelization and vectorization makes the proposed framework applicable for large-scale graph structures. The efficiency of the model is shown through a comprehensive set of numerical experiments.