רוברט מושקוביץ'

אקדמי בכיר

THAAD

Efficient matching queries under temporal abstraction for anomaly detection

In this paper, we present a novel algorithm and efficient data structure for anomaly detection based on temporal data. Time-series data are represented by a sequence of symbolic time intervals, describing increasing and decreasing trends, in a compact way using gradient temporal abstraction technique. Then we identify unusual subsequences in the resulting sequence using dynamic data structure based on the geometric observations supporting polylogarithmic update and query times. Moreover, we introduce a new parameter to control the pairwise difference between the corresponding symbols in addition to a distance metric between the subsequences. THAAD is evaluated on a large dataset of public DNS attacks and compared with a number of baseline algorithms. We find that THAAD outperforms other approaches, achieving up to 11% improvement in True Positive Rate (TPR) and False Negative Rate (FNR).

שפת פרסום אנגלית
כתב עת Performance Evaluation
כרך 149-150
סטטוס פרסום פורסם - 01.09.2021
מספר מאמר 102219

Keywords

Anomaly detection
Approximate string matching
Dynamic query data structure
Temporal data mining

ASJC Scopus subject areas

Software
Modeling and Simulation
Hardware and Architecture
Computer Networks and Communications
גישה למסמך
10.1016/j.peva.2021.102219
קבצים וקישורים אחרים
Link to publication in Scopus