Online Privacy-Preserving Data-Driven Network Anomaly Detection

Online Privacy-Preserving Data-Driven Network Anomaly Detection
复制标题

DOI:
10.1109/jsac.2022.3142302
复制
发表时间:
2022-03
影响因子:
16.4
通讯作者:
M. N. Kurt;Y. Yilmaz;Xiaodong Wang;P. Mosterman
M. N. Kurt;Y. Yilmaz;Xiaodong Wang;P. Mosterman
中科院分区:
计算机科学1区
文献类型:
--
作者:
M. N. Kurt;Y. Yilmaz;Xiaodong Wang;P. Mosterman

文献摘要

被引文献

相似文献

我们研究在线隐私保护异常检测的设置中,数据分布在网络和本地敏感的每个节点,概率数据模型是未知的。我们设计并分析了一个数据驱动的解决方案,其中每个节点观察一个高维数据流,它计算一个本地离群分数。然后对该分数进行扰动、加密并发送给网络运营商。然后,网络运营商通过网络解密聚合统计数据,并通过所提出的广义累积和(GCNUM)算法执行在线网络异常检测。我们推导出该算法的平均虚警周期的渐近下界和渐近近似。此外,我们得到了一个渐近上界和渐近近似的平均检测延迟的算法在一定的异常。我们展示了异常检测性能和差分隐私级别之间的分析权衡,通过局部扰动噪声控制。实验结果表明,该算法在真实的物联网(IoT)网络中,针对UDP洪泛和垃圾邮件攻击,在隐私和快速异常检测之间取得了较好的折衷。
We study online privacy-preserving anomaly detection in a setting in which the data are distributed over a network and locally sensitive to each node, and a probabilistic data model is unknown. We design and analyze a data-driven solution scheme where each node observes a high-dimensional data stream for which it computes a local outlierness score. This score is then perturbed, encrypted, and sent to a network operator. The network operator then decrypts an aggregate statistic over the network and performs online network anomaly detection via the proposed generalized cumulative sum (CUSUM) algorithm. We derive an asymptotic lower bound and an asymptotic approximation for the average false alarm period of the proposed algorithm. Additionally, we derive an asymptotic upper bound and asymptotic approximation for the average detection delay of the proposed algorithm under a certain anomaly. We show the analytical tradeoff between the anomaly detection performance and the differential privacy level, controlled via the local perturbation noise. Experiments illustrate that the proposed algorithm offers a good tradeoff between privacy and quick anomaly detection against the UDP flooding and spam attacks in a real Internet of Things (IoT) network.