Towards Unsupervised Time-Series Anomaly Detection for Virtual Cloud Networks

被引:0
作者
Ma, Zixuan [1 ,2 ]
Li, Chen [1 ,2 ]
Zhang, Kun [1 ,2 ]
Tu, Bibo [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100085, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100049, Peoples R China
关键词
Virtual cloud network; anomaly detection; cloud security; network security; time-series data;
D O I
10.1109/TIFS.2025.3561672
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Virtual cloud network (VCN) is a fundamental cloud resource for endpoints (VMs or containers) to communicate with each other and with the outside. Anomaly detection, a key security approach for VCNs, faces serious challenges: 1) Current feature models are difficult to apply to VCNs with significant differences from traditional networks. 2) Current anomaly detection models lack the adaptability to learn multiple normal patterns simultaneously. The need to train a dedicated model for each endpoint causes serious scalability problems in VCNs. 3) Current anomaly detection models have difficulty addressing the complex temporal dependency and non-stationarity of VCNs. To address these challenges, we propose a new multilevel feature model MFM and a new unsupervised time-series anomaly detection model GTGmVAE. By combining the basic features with the topology features specifically designed for VCNs, MFM effectively characterizes the patterns of VCNs. GTGmVAE combines the new local-global feature extractor with the latent space following a Gaussian mixture distribution to achieve the strong adaptability to learn multiple normal patterns simultaneously, and achieves the strong temporal modeling capability to effectively address the complex temporal dependency and non-stationarity of VCNs by adequately modeling the global temporal dependencies of the input samples and latent variables. Extensive experiments on the VCN anomaly detection dataset CIC-IDS2018 and the time-series anomaly detection benchmark dataset SMD show that GTGmVAE with MFM achieves the desirable performance, and GTGmVAE outperforms all nine representative state-of-the-art detection models.
引用
收藏
页码:4322 / 4337
页数:16
相关论文
共 35 条
[1]   Hypervisor-based cloud intrusion detection through online multivariate statistical change tracking [J].
Aldribi, Abdulaziz ;
Traore, Issa ;
Moa, Belaid ;
Nwamuo, Onyekachi .
COMPUTERS & SECURITY, 2020, 88
[2]  
[Anonymous], 2011, The Nist Defnition of Cloud Computing, DOI DOI 10.6028/NIST.SP.800-145
[3]  
[Anonymous], 2016, Cisco visual networking index: Global mobile data traffic forecast update, 2015-2020 white paper
[4]  
Arzani B, 2020, PROCEEDINGS OF THE 17TH USENIX SYMPOSIUM ON NETWORKED SYSTEMS DESIGN AND IMPLEMENTATION, P797
[5]  
Can. Inst. for Cybersecurity, 2022, Cicflowmeter
[6]  
Can. Inst. for Cybersecurity, 2018, CSE-CIC-IDS2018 on AWS
[7]  
Chung J, 2015, ADV NEUR IN, V28
[8]  
Daehyung Park, 2018, IEEE Robotics and Automation Letters, V3, P1544, DOI [10.1109/lra.2018.2801475, 10.1109/LRA.2018.2801475]
[9]   Switching Gaussian Mixture Variational RNN for Anomaly Detection of Diverse CDN Websites [J].
Dai, Liang ;
Chen, Wenchao ;
Liu, Yanwei ;
Argyriou, Antonios ;
Liu, Chang ;
Lin, Tao ;
Wang, Penghui ;
Xu, Zhen ;
Chen, Bo .
IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2022), 2022, :300-309
[10]   SDFVAE: Static and Dynamic Factorized VAE for Anomaly Detection of Multivariate CDN KPIs [J].
Dai, Liang ;
Lin, Tao ;
Liu, Chang ;
Jiang, Bo ;
Liu, Yanwei ;
Xu, Zhen ;
Zhang, Zhi-Li .
PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, :3076-3086