Anomaly detection based on a dynamic Markov model

被引:54
|
作者
Ren, Huorong [1 ,2 ]
Ye, Zhixing [1 ,2 ]
Li, Zhiwu [1 ,3 ]
机构
[1] Xidian Univ, Sch Electromech Engn, Xian 710071, Peoples R China
[2] Minist Educ, Key Lab Elect Equipment Struct Design, Xian 710071, Peoples R China
[3] Macau Univ Sci & Technol, Inst Syst Engn, Taipa 999078, Macau, Peoples R China
关键词
Sequence data; Anomaly detection; Markov model; Higher order Markov model; TIME-SERIES; STATISTICS; ALGORITHMS; SYSTEMS;
D O I
10.1016/j.ins.2017.05.021
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection in sequence data is becoming more and more important in a wide variety of application domains such as credit card fraud detection, health care in medical field, and intrusion detection in cyber security. In the existing anomaly detection approaches, Markov chain techniques are widely accepted for their simple realization and few parameters. However, the short memory property of a classical Markov model ignores the interaction among data, and the long memory property of a higher order Markov model clouds the relationship between the previous data and current test data, and reduces the reliability of the model. Besides, both of these models cannot successfully describe the sequences changing with a tendency. In this paper, we propose an anomaly detection approach based on a dynamic Markov model. This approach segments sequence data by a sliding window. In the sliding window, we define the states of data according to the value of the data and establish a higher order Markov model with a proper order consequently, to balance the length of the memory property and keep up with the trend of sequences. In addition, an anomaly substitution strategy is proposed to prevent the detected anomalies from impacting the building of the models and keep anomaly detection continuously. The experimental results using simulated datasets and real-world datasets have demonstrated that the proposed approach improves the adaptability and stability of anomaly detection in sequence data. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:52 / 65
页数:14
相关论文
共 50 条
  • [1] TIME SERIES ANOMALY DETECTION BASED ON FUZZY DYNAMIC MARKOV MODEL
    Li, Xudong
    Zhao, Lan
    Gao, Tan
    Chen, Wen
    JOURNAL OF NONLINEAR AND CONVEX ANALYSIS, 2021, 22 (09) : 1821 - 1830
  • [2] Anomaly detection based on a granular Markov model
    Zhou, Yanjun
    Ren, Huorong
    Li, Zhiwu
    Pedrycz, Witold
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 187
  • [3] An Anomaly Detection System based on Hide Markov Model for MANET
    Ye, Xia
    Li, Junshan
    Li, Yanling
    2010 6TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS NETWORKING AND MOBILE COMPUTING (WICOM), 2010,
  • [4] Anomaly Detection and Classification in Multispectral Time Series Based on Hidden Markov Models
    Leon-Lopez, Kareth M.
    Mouret, Florian
    Arguello, Henry
    Tourneret, Jean-Yves
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60
  • [5] Anomaly Detection Boundary Based on the Moving Averages of Markov Chain Model
    Chen, Deqiang
    2015 12th International Conference on Fuzzy Systems and Knowledge Discovery (FSKD), 2015, : 1532 - 1536
  • [6] Workload hidden Markov model for anomaly detection
    Garcia, Juan Manuel
    Navarrete, Tomas
    Orozco, Carlos
    SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : 56 - +
  • [7] A Hidden Markov Model-Based Method for Virtual Machine Anomaly Detection
    Shi, Chaochen
    Yu, Jiangshan
    PROVABLE SECURITY, PROVSEC 2019, 2019, 11821 : 372 - 380
  • [8] A Hyperspectral Imagery Anomaly Detection Algorithm Based on Gauss-Markov Model
    Gao Kun
    Liu Ying
    Wang Li-jing
    Zhu Zhen-yu
    Cheng Hao-bo
    SPECTROSCOPY AND SPECTRAL ANALYSIS, 2015, 35 (10) : 2846 - 2850
  • [9] The Application of Markov Model Based Equivalence Class Generalization in Network Anomaly Detection
    Peng, Siyuan
    Wang, Guoyin
    Li, Zhixing
    Yang, Jie
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA ANALYSIS (ICCCBDA 2017), 2017, : 389 - 393
  • [10] Semi-Markov Switching Vector Autoregressive Model-Based Anomaly Detection in Aviation Systems
    Melnyk, Igor
    Banerjee, Arindam
    Matthews, Bryan
    Oza, Nikunj
    KDD'16: PROCEEDINGS OF THE 22ND ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2016, : 1065 - 1074