Anomaly detection based on a dynamic Markov model

被引:55
作者
Ren, Huorong [1 ,2 ]
Ye, Zhixing [1 ,2 ]
Li, Zhiwu [1 ,3 ]
机构
[1] Xidian Univ, Sch Electromech Engn, Xian 710071, Peoples R China
[2] Minist Educ, Key Lab Elect Equipment Struct Design, Xian 710071, Peoples R China
[3] Macau Univ Sci & Technol, Inst Syst Engn, Taipa 999078, Macau, Peoples R China
关键词
Sequence data; Anomaly detection; Markov model; Higher order Markov model; TIME-SERIES; STATISTICS; ALGORITHMS; SYSTEMS;
D O I
10.1016/j.ins.2017.05.021
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection in sequence data is becoming more and more important in a wide variety of application domains such as credit card fraud detection, health care in medical field, and intrusion detection in cyber security. In the existing anomaly detection approaches, Markov chain techniques are widely accepted for their simple realization and few parameters. However, the short memory property of a classical Markov model ignores the interaction among data, and the long memory property of a higher order Markov model clouds the relationship between the previous data and current test data, and reduces the reliability of the model. Besides, both of these models cannot successfully describe the sequences changing with a tendency. In this paper, we propose an anomaly detection approach based on a dynamic Markov model. This approach segments sequence data by a sliding window. In the sliding window, we define the states of data according to the value of the data and establish a higher order Markov model with a proper order consequently, to balance the length of the memory property and keep up with the trend of sequences. In addition, an anomaly substitution strategy is proposed to prevent the detected anomalies from impacting the building of the models and keep anomaly detection continuously. The experimental results using simulated datasets and real-world datasets have demonstrated that the proposed approach improves the adaptability and stability of anomaly detection in sequence data. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:52 / 65
页数:14
相关论文
共 50 条
  • [41] LSTM-Markov based efficient anomaly detection algorithm for IoT environment
    Shanmuganathan, V
    Suresh, A.
    APPLIED SOFT COMPUTING, 2023, 136
  • [42] Generalized Pareto Model Based on Particle Swarm Optimization for Anomaly Detection
    Huang, Yan
    Du, Fuyu
    Chen, Jian
    Chen, Yan
    Wang, Qicong
    Li, Maozhen
    IEEE ACCESS, 2019, 7 : 176329 - 176338
  • [43] Model-centered Ensemble for Anomaly Detection in Time Series
    Trentini, Erick L.
    Coelho da Silva, Ticiana L.
    Melo Junior, Leopoldo
    de Macedo, Jose F.
    ICAART: PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AGENTS AND ARTIFICIAL INTELLIGENCE, VOL 2, 2020, : 700 - 707
  • [44] Multivariate Time Series Anomaly Detection Based on Time-Frequency Dynamic Analysis
    Yuan, Anni
    Zou, Chunming
    Wang, Yong
    Hu, Jinming
    2024 13TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS, ICCCAS 2024, 2024, : 375 - 379
  • [45] Satellite On-Orbit Anomaly Detection Method Based on a Dynamic Threshold and Causality Pruning
    Chen, Siya
    Jin, G.
    Ma, Xinyu
    IEEE ACCESS, 2021, 9 : 86751 - 86758
  • [46] A Dynamic Network Anomaly Detection Method Based on Trend Analysis
    Sun, Tong
    Liu, Yan
    Chen, Jing
    PROCEEDINGS OF 2017 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2017, : 405 - 411
  • [47] Anomaly Detection in Dynamic Systems Using Weak Estimators
    Zhan, Justin
    Oommen, B. John
    Crisostomo, Johanna
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2011, 11 (01)
  • [48] SCConv-Denoising Diffusion Probabilistic Model Anomaly Detection Based on TimesNet
    Zhou, Jingquan
    Yang, Xinhe
    Ren, Zhu
    ELECTRONICS, 2025, 14 (04):
  • [49] Combining Hidden Markov Models for Improved Anomaly Detection
    Khreich, Wael
    Granger, Eric
    Sabourin, Robert
    Miri, Ali
    2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 965 - +
  • [50] Anomaly detection model based on data stream clustering
    Chunyong Yin
    Sun Zhang
    Zhichao Yin
    Jin Wang
    Cluster Computing, 2019, 22 : 1729 - 1738