Academic Journal

Scan statistics for the online detection of locally anomalous subgraphs

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: Scan statistics for the online detection of locally anomalous subgraphs
Συγγραφείς: Neil, Joshua
Πηγή: Mathematics & Statistics ETDs
Στοιχεία εκδότη: UNM Digital Repository
Έτος έκδοσης: 2011
Συλλογή: UNM Digital Repository (The University of New Mexico)
Θεματικοί όροι: Computer networks--Security measures--Statistical methods, Computer networks--Monitoring--Statistical methods, Computer security--Statistical methods
Περιγραφή: Identifying anomalies in computer networks is a challenging and complex problem. Often, anomalies occur in extremely local areas of the network. Locality is complex in this setting, since we have an underlying graph structure. To identify local anomalies, we introduce a scan statistic for data extracted from the edges of a graph over time. In the computer network setting, the data on these edges are multivariate measures of the communications between two distinct machines, over time. We describe two shapes for capturing locality in the graph: the star and the k-path. While the star shape is not new to the literature, the path shape, when used as a scan window, appears to be novel. Both of these shapes are motivated by hacker behaviors observed in real attacks. A hacker who is using a single central machine to examine other machines creates a star-shaped anomaly on the edges emanating from the central node. Paths represent traversal of a hacker through a network, using a set of machines in sequence. To identify local anomalies, these shapes are enumerated over the entire graph, over a set of sliding time windows. Local statistics in each window are compared with their historic behavior to capture anomalies within the window. These local statistics are model-based. To capture the communications between computers, we have applied two different models, observed and hidden Markov models, to each edge in the network. These models have been effective in handling various aspects of this type of data, but do not completely describe the data. Therefore, we also present ongoing work in the modeling of host-to-host communications in a computer network. Data speeds on larger networks require online detection to be nimble. We describe a full anomaly detection system, which has been applied to a corporate sized network and achieves better than real-time analysis speed. We present results on simulated data whose parameters were estimated from real network data. In addition, we present a result from our analysis of a real, ...
Τύπος εγγράφου: text
Περιγραφή αρχείου: application/pdf
Γλώσσα: English
Relation: https://digitalrepository.unm.edu/math_etds/60; https://digitalrepository.unm.edu/context/math_etds/article/1059/viewcontent/dissertationwithsig.pdf
Διαθεσιμότητα: https://digitalrepository.unm.edu/math_etds/60
https://digitalrepository.unm.edu/context/math_etds/article/1059/viewcontent/dissertationwithsig.pdf
Αριθμός Καταχώρησης: edsbas.23FD0723
Βάση Δεδομένων: BASE
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://digitalrepository.unm.edu/math_etds/60#
    Name: EDS - BASE (ns324271)
    Category: fullText
    Text: View record from BASE
Header DbId: edsbas
DbLabel: BASE
An: edsbas.23FD0723
RelevancyScore: 773
AccessLevel: 3
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 772.654235839844
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Scan statistics for the online detection of locally anomalous subgraphs
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Neil%2C+Joshua%22">Neil, Joshua</searchLink>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: Mathematics & Statistics ETDs
– Name: Publisher
  Label: Publisher Information
  Group: PubInfo
  Data: UNM Digital Repository
– Name: DatePubCY
  Label: Publication Year
  Group: Date
  Data: 2011
– Name: Subset
  Label: Collection
  Group: HoldingsInfo
  Data: UNM Digital Repository (The University of New Mexico)
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+networks--Security+measures--Statistical+methods%22">Computer networks--Security measures--Statistical methods</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+networks--Monitoring--Statistical+methods%22">Computer networks--Monitoring--Statistical methods</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security--Statistical+methods%22">Computer security--Statistical methods</searchLink>
– Name: Abstract
  Label: Description
  Group: Ab
  Data: Identifying anomalies in computer networks is a challenging and complex problem. Often, anomalies occur in extremely local areas of the network. Locality is complex in this setting, since we have an underlying graph structure. To identify local anomalies, we introduce a scan statistic for data extracted from the edges of a graph over time. In the computer network setting, the data on these edges are multivariate measures of the communications between two distinct machines, over time. We describe two shapes for capturing locality in the graph: the star and the k-path. While the star shape is not new to the literature, the path shape, when used as a scan window, appears to be novel. Both of these shapes are motivated by hacker behaviors observed in real attacks. A hacker who is using a single central machine to examine other machines creates a star-shaped anomaly on the edges emanating from the central node. Paths represent traversal of a hacker through a network, using a set of machines in sequence. To identify local anomalies, these shapes are enumerated over the entire graph, over a set of sliding time windows. Local statistics in each window are compared with their historic behavior to capture anomalies within the window. These local statistics are model-based. To capture the communications between computers, we have applied two different models, observed and hidden Markov models, to each edge in the network. These models have been effective in handling various aspects of this type of data, but do not completely describe the data. Therefore, we also present ongoing work in the modeling of host-to-host communications in a computer network. Data speeds on larger networks require online detection to be nimble. We describe a full anomaly detection system, which has been applied to a corporate sized network and achieves better than real-time analysis speed. We present results on simulated data whose parameters were estimated from real network data. In addition, we present a result from our analysis of a real, ...
– Name: TypeDocument
  Label: Document Type
  Group: TypDoc
  Data: text
– Name: Format
  Label: File Description
  Group: SrcInfo
  Data: application/pdf
– Name: Language
  Label: Language
  Group: Lang
  Data: English
– Name: NoteTitleSource
  Label: Relation
  Group: SrcInfo
  Data: https://digitalrepository.unm.edu/math_etds/60; https://digitalrepository.unm.edu/context/math_etds/article/1059/viewcontent/dissertationwithsig.pdf
– Name: URL
  Label: Availability
  Group: URL
  Data: https://digitalrepository.unm.edu/math_etds/60<br />https://digitalrepository.unm.edu/context/math_etds/article/1059/viewcontent/dissertationwithsig.pdf
– Name: AN
  Label: Accession Number
  Group: ID
  Data: edsbas.23FD0723
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edsbas&AN=edsbas.23FD0723
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Text: English
    Subjects:
      – SubjectFull: Computer networks--Security measures--Statistical methods
        Type: general
      – SubjectFull: Computer networks--Monitoring--Statistical methods
        Type: general
      – SubjectFull: Computer security--Statistical methods
        Type: general
    Titles:
      – TitleFull: Scan statistics for the online detection of locally anomalous subgraphs
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Neil, Joshua
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Type: published
              Y: 2011
          Identifiers:
            – Type: issn-locals
              Value: edsbas
          Titles:
            – TitleFull: Mathematics & Statistics ETDs
              Type: main
ResultId 1