Anomaly detection based on a dynamic Markov model

被引:54
|
作者
Ren, Huorong [1 ,2 ]
Ye, Zhixing [1 ,2 ]
Li, Zhiwu [1 ,3 ]
机构
[1] Xidian Univ, Sch Electromech Engn, Xian 710071, Peoples R China
[2] Minist Educ, Key Lab Elect Equipment Struct Design, Xian 710071, Peoples R China
[3] Macau Univ Sci & Technol, Inst Syst Engn, Taipa 999078, Macau, Peoples R China
关键词
Sequence data; Anomaly detection; Markov model; Higher order Markov model; TIME-SERIES; STATISTICS; ALGORITHMS; SYSTEMS;
D O I
10.1016/j.ins.2017.05.021
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection in sequence data is becoming more and more important in a wide variety of application domains such as credit card fraud detection, health care in medical field, and intrusion detection in cyber security. In the existing anomaly detection approaches, Markov chain techniques are widely accepted for their simple realization and few parameters. However, the short memory property of a classical Markov model ignores the interaction among data, and the long memory property of a higher order Markov model clouds the relationship between the previous data and current test data, and reduces the reliability of the model. Besides, both of these models cannot successfully describe the sequences changing with a tendency. In this paper, we propose an anomaly detection approach based on a dynamic Markov model. This approach segments sequence data by a sliding window. In the sliding window, we define the states of data according to the value of the data and establish a higher order Markov model with a proper order consequently, to balance the length of the memory property and keep up with the trend of sequences. In addition, an anomaly substitution strategy is proposed to prevent the detected anomalies from impacting the building of the models and keep anomaly detection continuously. The experimental results using simulated datasets and real-world datasets have demonstrated that the proposed approach improves the adaptability and stability of anomaly detection in sequence data. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:52 / 65
页数:14
相关论文
共 50 条
  • [21] Dynamic double threshold energy detection based on Markov Model in cognitive radio
    Liu Y.
    Liang J.
    Xiao N.
    Hu Y.
    Hu M.
    Liu, Yulei (huapofeixue@sina.com), 1600, Science Press (38): : 2590 - 2597
  • [22] Adaptive Hidden Markov Model With Anomaly States for Price Manipulation Detection
    Cao, Yi
    Li, Yuhua
    Coleman, Sonya
    Belatreche, Ammar
    McGinnity, Thomas Martin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2015, 26 (02) : 318 - 330
  • [23] An Efficient Hidden Markov Model For Anomaly Detection In CAN Bus Networks
    Boumiza, Safa
    Braham, Rafik
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 482 - 487
  • [24] Dynamic Anomaly Detection Using Vector Autoregressive Model
    Li, Yuemeng
    Lu, Aidong
    Wu, Xintao
    Yuan, Shuhan
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PAKDD 2019, PT I, 2019, 11439 : 600 - 611
  • [25] Online Anomaly Detection Under Markov Statistics With Controllable Type-I Error
    Ozkan, Huseyin
    Ozkan, Fatih
    Kozat, Suleyman S.
    IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2016, 64 (06) : 1435 - 1445
  • [26] Time Series Anomaly Detection Based on Score Generative Model
    Zhou H.
    Yu K.
    Wu X.
    Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2024, 47 (02): : 51 - 57
  • [27] A Multi-Order Markov Chain Based Scheme for Anomaly Detection
    Sha, Wenyao
    Zhu, Yongxin
    Huang, Tian
    Qiu, Meikang
    Zhu, Yan
    Zhang, Qiannan
    2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW), 2013, : 83 - 88
  • [28] THGNN: An Embedding-based Model for Anomaly Detection in Dynamic Heterogeneous Social Networks
    Li, Yilin
    Zhu, Jiaqi
    Zhang, Congcong
    Yang, Yi
    Zhang, Jiawen
    Qiao, Ying
    Wang, Hongan
    PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2023, 2023, : 1368 - 1378
  • [29] Method of Behavior Modeling for Detection of Anomaly Behavior using Hidden Markov Model
    Ishii, Haruka
    Kimino, Keisuke
    Inoue, Masahiro
    Arahira, Masaki
    Suzuki, Yayoi
    2018 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2018, : 151 - 154
  • [30] Efficient anomaly detection by modeling privilege flows using hidden Markov model
    Cho, SB
    Park, HJ
    COMPUTERS & SECURITY, 2003, 22 (01) : 45 - 55