MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams
arXiv:2009.08451 · doi:10.1145/3442381.3450023
Abstract
Given a stream of entries in a multi-aspect data setting i.e., entries having multiple dimensions, how can we detect anomalous activities in an unsupervised manner? For example, in the intrusion detection setting, existing work seeks to detect anomalous events or edges in dynamic graph streams, but this does not allow us to take into account additional attributes of each entry. Our work aims to define a streaming multi-aspect data anomaly detection framework, termed MSTREAM which can detect unusual group anomalies as they occur, in a dynamic manner. MSTREAM has the following properties: (a) it detects anomalies in multi-aspect data including both categorical and numeric attributes; (b) it is online, thus processing each record in constant time and constant memory; (c) it can capture the correlation between multiple aspects of the data. MSTREAM is evaluated over the KDDCUP99, CICIDS-DoS, UNSW-NB 15 and CICIDS-DDoS datasets, and outperforms state-of-the-art baselines.
The Web Conference (WWW), 2021
References in corpus (4)
Cited by in corpus (8)
- A Comprehensive Survey on Graph Anomaly Detection with Deep Learning
- Anomaly Detection in Dynamic Graphs: A Comprehensive Survey
- Adaptive Model Pooling for Online Deep Anomaly Detection from a Complex Evolving Data Stream
- METER: A Dynamic Concept Adaptation Framework for Online Anomaly Detection
- Subset Node Anomaly Tracking over Large Dynamic Graphs
- 3D-IDS: Doubly Disentangled Dynamic Intrusion Detection
- Fast and Multi-aspect Mining of Complex Time-stamped Event Streams
- CyberCScope: Mining Skewed Tensor Streams and Online Anomaly Detection in Cybersecurity Systems