arrow
Return

Comparing Threshold Selection Methods for Network Anomaly Detection

delete2024-01-01
delete1
delete
OA
AI
A
Adrian Komadina *
M
Mislav Martinić
S
Stjepan Groš
Ž
Željka Mihajlović
DOI:10.1109/ACCESS.2024.3452168delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The use of unsupervised machine learning models for anomaly detection is a common thing nowadays. While many research papers focus on improving and testing these models, there is a lack of those that deal with threshold selection, which is an important step in implementing a good anomaly detection system. In this paper, we investigate different supervised and unsupervised threshold selection methods found in the network anomaly detection literature. A total of five supervised and twenty unsupervised methods were found, all of which are described, categorized, and implemented in this paper. The unsupervised methods were further categorized according to the input data they expect, the type of output data they produce, and whether they are parametric or not, and divided into six groups according to the idea behind these methods: Statistics-based, Distribution-based, Clustering-based, Density-based, Graphical-based methods and Other. To test all the methods found, two different testing scenarios are created. The first one focuses on using data with anomalies and the second one uses only the normal data. Based on these two scenarios, tests were performed with real firewall log data containing three types of injected anomalies. The results are presented in the form of boxplots of the Matthews correlation coefficient for nine datasets. To draw a conclusion, both the method groups and the individual methods were compared in terms of evaluation metrics and execution times as well as in comparison to the methods already implemented in the PyThresh toolkit.
Keywords:
Anomaly detection
Measurement
Receivers
Machine learning
Intrusion detection
Unsupervised learning
network data
threshold selection
unsupervised learning

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

U
University of Zagreb
Scholars:
1.8W
Papers: 1.3W
Citations: 1.1W
Cited Papers

Cited Papers

Engineering bispecific antibodies
err1993-08-01
err0
PREAI
errPhilipp Holliger; Greg Winter
errShare
errSave
Gene-Immune Therapy of Cancer: Approaches and Problems
err2022-05-15
err0
errOAAI
errI. V. Alekseenko; V. V. Pleshkan; A. I. Kuzmich; S. A. Kondratieva; E. D. Sverdlov
errShare
errSave
The MVTec Anomaly Detection Dataset: A Comprehensive Real-World Dataset for Unsupervised Anomaly Detection
err2021-01-06
err177
errOAAI
errBergmann, Paul; Batzner, Kilian; Fauser, Michael; Sattlegger, David; Steger, Carsten
errShare
errSave
adVAE: A self-adversarial variational autoencoder with Gaussian anomaly prior knowledge for anomaly detection
err2020-02-01
err76
errOAAI
errWang, Xuhong; Du, Ying; Lin, Shijie; Cui, Ping; Shen, Yuntian; Yang, Yupu
errShare
errSave
errShare
errSave
errShare
errSave
Rates of protonation of some amide and peptide nickel(II) complexes
err2002-05-01
err0
PREAI
errCaroline F. V. Mason; Phyllis I. Chamberlain; Ralph G. Wilkins
errShare
errSave
Tumours of the Skin
err1973-01-01
err0
PREAI
errUlla Iversen; Olav Hilmar Iversen
errShare
errSave
Progress in Outlier Detection Techniques: A Survey
err2019-01-01
err320
errOAAI
errWang, Hongzhi; Bah, Mohamed Jaward; Hammad, Mohamed
errShare
errSave
researcher View more