skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Anomaly Detection in Dynamic Networks

Technical Report ·
DOI:https://doi.org/10.2172/1160097· OSTI ID:1160097
 [1]
  1. Los Alamos National Lab. (LANL), Los Alamos, NM (United States)

Anomaly detection in dynamic communication networks has many important security applications. These networks can be extremely large and so detecting any changes in their structure can be computationally challenging; hence, computationally fast, parallelisable methods for monitoring the network are paramount. For this reason the methods presented here use independent node and edge based models to detect locally anomalous substructures within communication networks. As a first stage, the aim is to detect changes in the data streams arising from node or edge communications. Throughout the thesis simple, conjugate Bayesian models for counting processes are used to model these data streams. A second stage of analysis can then be performed on a much reduced subset of the network comprising nodes and edges which have been identified as potentially anomalous in the first stage. The first method assumes communications in a network arise from an inhomogeneous Poisson process with piecewise constant intensity. Anomaly detection is then treated as a changepoint problem on the intensities. The changepoint model is extended to incorporate seasonal behavior inherent in communication networks. This seasonal behavior is also viewed as a changepoint problem acting on a piecewise constant Poisson process. In a static time frame, inference is made on this extended model via a Gibbs sampling strategy. In a sequential time frame, where the data arrive as a stream, a novel, fast Sequential Monte Carlo (SMC) algorithm is introduced to sample from the sequence of posterior distributions of the change points over time. A second method is considered for monitoring communications in a large scale computer network. The usage patterns in these types of networks are very bursty in nature and don’t fit a Poisson process model. For tractable inference, discrete time models are considered, where the data are aggregated into discrete time periods and probability models are fitted to the communication counts. In a sequential analysis, anomalous behavior is then identified from outlying behavior with respect to the fitted predictive probability models. Seasonality is again incorporated into the model and is treated as a changepoint model on the transition probabilities of a discrete time Markov process. Second stage analytics are then developed which combine anomalous edges to identify anomalous substructures in the network.

Research Organization:
Los Alamos National Laboratory (LANL), Los Alamos, NM (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC52-06NA25396
OSTI ID:
1160097
Report Number(s):
LA-UR-14-28026
Country of Publication:
United States
Language:
English

Similar Records

Adaptive Sequential Monte Carlo for Multiple Changepoint Analysis
Journal Article · Sat May 21 00:00:00 EDT 2016 · Journal of Computational and Graphical Statistics · OSTI ID:1160097

Designing Size Consistent Statistics for Accurate Anomaly Detection in Dynamic Networks
Journal Article · Mon Apr 16 00:00:00 EDT 2018 · ACM Transactions on Knowledge Discovery from Data · OSTI ID:1160097

A multi-level anomaly detection algorithm for time-varying graph data with interactive visualization
Journal Article · Fri Jan 01 00:00:00 EST 2016 · Social Network Analysis and Mining · OSTI ID:1160097