Classification of periodic arrivals in event time data for filtering computer network traffic

Classification of periodic arrivals in event time data for filtering computer network traffic
复制标题

DOI:
10.1007/s11222-020-09943-9
复制
发表时间:
2020-04
影响因子:
2.2
通讯作者:
Francesco Sanna Passino;N. Heard
Francesco Sanna Passino;N. Heard
中科院分区:
数学2区
文献类型:
--
作者:
Francesco Sanna Passino;N. Heard

文献摘要

被引文献

相似文献

在真实世界的事件时间数据中经常可以观察到周期性模式,可能与非周期性到达时间混合。为了建模的目的,有必要正确区分这两种类型的事件。这项任务在计算机网络安全中具有特别重要的意义;在那里,分离计算机网络中的自动轮询流量和人为活动对于为正常活动构建现实的统计模型非常重要,而这些模型又可以用于异常检测。由于自动化事件通常以固定的周期发生,因此使用傅立叶分析的统计测试可以有效地检测到达时间是否存在自动化组件。在本文中,包含自动化事件的到达时间序列将被进一步检查,以区分轮询和非周期性活动。这是首先实现使用一个简单的混合模型的单位圆上的角度位置的每个事件的时间上的p-clock,whereprepresents与自动化活动相关联的主要周期性的基础上,然后通过结合第二个信息源,每个事件的一天中的时间,该模型被扩展。利用共轭贝叶斯模型的有效实现进行了讨论,并在伦敦帝国理工学院收集的真实的网络流量数据的性能进行评估。
Periodic patterns can often be observed in real-world event time data, possibly mixed with non-periodic arrival times. For modelling purposes, it is necessary to correctly distinguish the two types of events. This task has particularly important implications in computer network security; there, separating automated polling traffic and human-generated activity in a computer network is important for building realistic statistical models for normal activity, which in turn can be used for anomaly detection. Since automated events commonly occur at a fixed periodicity, statistical tests using Fourier analysis can efficiently detect whether the arrival times present an automated component. In this article, sequences of arrival times which contain automated events are further examined, to separate polling and non-periodic activity. This is first achieved using a simple mixture model on the unit circle based on the angular positions of each event time on thep-clock, whereprepresents the main periodicity associated with the automated activity; this model is then extended by combining a second source of information, the time of day of each event. Efficient implementations exploiting conjugate Bayesian models are discussed, and performance is assessed on real network flow data collected at Imperial College London.