通过相似性学习实现事件触发流量序列的异常检测。
Anomaly Detection in Event-triggered Traffic Time Series via Similarity Learning
- 用多分辨率自编码器与高斯混合模型学习序列低维表示
- 在多个数据集上异常检测准确率显著优于现有方法
- 适合安全监控中无标签事件序列的相似性分析
时间序列分析在网络安全领域如入侵检测和设备识别中已取得显著成效。学习多个时间序列间的相似性是下游分析的基础,但事件触发序列复杂的时序动态使得难以确定适用于异常检测与聚类等任务的合适相似性度量。本文提出一种无监督学习框架,旨在从一组事件触发时间序列中学习相似性。该框架结合分层多分辨率序列自编码器与高斯混合模型(GMM),有效提取时间序列的低维表示,并生成可解释的相似性度量。通过大量定性与定量实验验证,该方法在多个数据集上显著优于当前最优方法,为系统化建模和学习多组事件触发序列间的相似性提供了基础方案。
原文摘要 · Abstract (English)
Time series analysis has achieved great success in cyber security such as intrusion detection and device identification. Learning similarities among multiple time series is a crucial problem since it serves as the foundation for downstream analysis. Due to the complex temporal dynamics of the event-triggered time series, it often remains unclear which similarity metric is appropriate for security-related tasks, such as anomaly detection and clustering. The overarching goal of this paper is to develop an unsupervised learning framework that is capable of learning similarities among a set of event-triggered time series. From the machine learning vantage point, the proposed framework harnesses the power of both hierarchical multi-resolution sequential autoencoders and the Gaussian Mixture Model (GMM) to effectively learn the low-dimensional representations from the time series. Finally, the obtained similarity measure can be easily visualized for the explanation. The proposed framework aspires to offer a stepping stone that gives rise to a systematic approach to model and learn similarities among a multitude of event-triggered time series. Through extensive qualitative and quantitative experiments, it is revealed that the proposed method outperforms state-of-the-art methods considerably.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。