arrow
返回

An anomaly detection framework for cyber-security data

delete2020-10-01
delete21
PRE
AI
M
Marina Evangelou *
N
Niall M. Adams
DOI:10.1016/j.cose.2020.101941delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Data-driven anomaly detection systems unrivalled potential as complementary defence systems to existing signature-based tools as the number of cyber attacks increases. In this manuscript an anomaly detection system is presented that detects any abnormal deviations from the normal behaviour of an individual device. Device behaviour is defined as the number of network traffic events involving the device of interest observed within a pre-specified time period. The behaviour of each device at normal state is modelled to depend on its observed historic behaviour. A number of statistical and machine learning approaches are explored for modelling this relationship and through a comparative study, the Quantile Regression Forests approach is found to have the best predictive power. Based on the prediction intervals of the Quantile Regression Forests an anomaly detection system is proposed that characterises as abnormal, any observed behaviour outside of these intervals. A series of experiments for contaminating normal device behaviour are presented for examining the performance of the anomaly detection system. Through the conducted analysis the proposed anomaly detection system is found to outperform two other detection systems. The presented work has been conducted on two enterprise networks. (c) 2020 Elsevier Ltd. All rights reserved.
Keyword:
NetFlow
Machine learning
Regression models
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

I
Imperial College London
学者数:
8.3W
论文数: 7.3W
被引数: 11.1W
引用论文

引用论文

Mixed-mode crack growth simulation in aviation engine compressor disk
err2021-04-01
err0
PREAI
errV. Shlyannikov; R. Yarullin; M. Yakovlev; V. Giannella; R. Citarella
err分享
err收藏
学者 查看更多内容