Anomaly detection based on a dynamic Markov model

被引:55
作者
Ren, Huorong [1 ,2 ]
Ye, Zhixing [1 ,2 ]
Li, Zhiwu [1 ,3 ]
机构
[1] Xidian Univ, Sch Electromech Engn, Xian 710071, Peoples R China
[2] Minist Educ, Key Lab Elect Equipment Struct Design, Xian 710071, Peoples R China
[3] Macau Univ Sci & Technol, Inst Syst Engn, Taipa 999078, Macau, Peoples R China
关键词
Sequence data; Anomaly detection; Markov model; Higher order Markov model; TIME-SERIES; STATISTICS; ALGORITHMS; SYSTEMS;
D O I
10.1016/j.ins.2017.05.021
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection in sequence data is becoming more and more important in a wide variety of application domains such as credit card fraud detection, health care in medical field, and intrusion detection in cyber security. In the existing anomaly detection approaches, Markov chain techniques are widely accepted for their simple realization and few parameters. However, the short memory property of a classical Markov model ignores the interaction among data, and the long memory property of a higher order Markov model clouds the relationship between the previous data and current test data, and reduces the reliability of the model. Besides, both of these models cannot successfully describe the sequences changing with a tendency. In this paper, we propose an anomaly detection approach based on a dynamic Markov model. This approach segments sequence data by a sliding window. In the sliding window, we define the states of data according to the value of the data and establish a higher order Markov model with a proper order consequently, to balance the length of the memory property and keep up with the trend of sequences. In addition, an anomaly substitution strategy is proposed to prevent the detected anomalies from impacting the building of the models and keep anomaly detection continuously. The experimental results using simulated datasets and real-world datasets have demonstrated that the proposed approach improves the adaptability and stability of anomaly detection in sequence data. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:52 / 65
页数:14
相关论文
共 50 条
  • [31] Network anomaly detection using Two-dimensional Hidden Markov Model-based Viterbi algorithm
    Alhaidari, Sulaiman
    Zohdy, Mohamed
    2019 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING (AITEST), 2019, : 17 - 18
  • [32] Anomaly detection of network-initiated LTE signaling traffic in wireless sensor and actuator networks based on a Hidden semi-Markov Model
    Bang, June-ho
    Cho, Young-jong
    Kang, Kyungran
    COMPUTERS & SECURITY, 2017, 65 : 108 - 120
  • [33] Anomaly intrusion detection based on dynamic cluster updating
    Oh, Sang-Hyun
    Lee, Won-Suk
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2007, 4426 : 737 - +
  • [34] Markov Chain-Based Feature Extraction for Anomaly Detection in Time Series and Its Industrial Application
    Zang, Dong
    Liu, Jinhai
    Wang, Huaizhen
    PROCEEDINGS OF THE 30TH CHINESE CONTROL AND DECISION CONFERENCE (2018 CCDC), 2018, : 1059 - 1063
  • [35] Bayesian Filtering for Dynamic Anomaly Detection and Tracking
    Forti, Nicola
    Millefiori, Leonardo M.
    Braca, Paolo
    Willett, Peter
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 2022, 58 (03) : 1528 - 1544
  • [36] Anomaly Detection of Wireless Relays Based on Markov Models Through the Wald-Wolfowitz Runs Test
    Huangfu, Yingying
    Zhou, Liang
    IEEE COMMUNICATIONS LETTERS, 2022, 26 (11) : 2562 - 2566
  • [37] EfficientTransformer: A Dynamic Anomaly Detection Model for Industrial Control Networks
    Liu, Jinyang
    Wang, Guogang
    Zong, Xuejun
    Ning, Bowei
    He, Kan
    IEEE ACCESS, 2025, 13 : 37931 - 37945
  • [38] Time-series anomaly detection using dynamic programming based longest common subsequence on sensor data
    Nguyen, Thi Phuong Quyen
    Phuc, Phan Nguyen Ky
    Yang, Chao -Lung
    Sutrisno, Hendri
    Luong, Bao-Han
    Le, Thi Huynh Anh
    Nguyen, Thanh Tung
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 213
  • [39] IoT Anomaly Detection Based on Autoencoder and Bayesian Gaussian Mixture Model
    Hou, Yunyun
    He, Ruiyu
    Dong, Jie
    Yang, Yangrui
    Ma, Wei
    ELECTRONICS, 2022, 11 (20)
  • [40] Anomaly detection of user behavior based on shell commands and homogeneous Markov chains
    Xinguang, Tian
    Miyi, Duan
    Wenfa, Li
    Chunlai, Sun
    CHINESE JOURNAL OF ELECTRONICS, 2008, 17 (02): : 231 - 236