arrow
返回

Network Anomaly Detection Using Exponential Random Graph Models and Autoregressive Moving Average

delete2021-01-01
delete8
delete
OA
AI
M
Michail Tsikerdekis *
S
Scott Waldron
A
Alex Emanuelson
DOI:10.1109/ACCESS.2021.3116575delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Network anomaly detection solutions are being used as defense against several attacks, especially those related to data exfiltration. Several methods exist in the literature, such as clustering or neural networks. However, these methods often focus on local and global network indicators instead of network structural properties, such as understanding which devices typically communicate with other devices. To address this literature gap, we propose a method that uses exponential random graph modeling to integrate network topology structure statistics in anomaly detection. We demonstrate the effectiveness of our method using real-world examples as a baseline for experiments on domain name system (DNS) data exfiltration scenarios. We highlight how our method provides better insight into how network traffic may alter network graph structure and how this can assist cybersecurity analysts in making better decisions in conjunction with existing intrusion detection systems. Finally, we compare and contrast the accuracy, false positive rate and computational overhead of our method with other methods.
Keyword:
Computer security
Anomaly detection
Protocols
Network topology
Tunneling
Time series analysis
Databases
Graph
ARMA
detection
anomaly
ERGM
network
exfiltration

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

W
western washington university
学者数:
1.4K
论文数: 1.1K
被引数: 2
引用论文

引用论文

暂无论文信息