An Evaluation of Time-Series Anomaly Detection in Computer Networks

Hong Nguyen, Arash Hajisafi, Alireza Abdoli, S. H. Kim, C. Shahabi
{"title":"An Evaluation of Time-Series Anomaly Detection in Computer Networks","authors":"Hong Nguyen, Arash Hajisafi, Alireza Abdoli, S. H. Kim, C. Shahabi","doi":"10.1109/ICOIN56518.2023.10049051","DOIUrl":null,"url":null,"abstract":"One critical issue in any network systems is failure detection. Failures not only impact the source network but also propagate through other communicating networks due to the butterfly effect, making root causing of failures even more challenging. Therefore, the necessity to detect failures and anomalies in computer networks is fundamental. Given the nature of computer networks, data is received in a time-series format where each time-point has temporal dependencies on others. As a result, time-series analysis stands out as a potential approach to deal with the task of network anomaly detection. In this paper, we conduct studies on multivariate time series anomaly detection, varying from traditional machine learning techniques to deep learning models. We show that the choice of models is not as important as the choice of pre-processing techniques. Interestingly, non-linear normalization can boost the performance of deep detectors by around 20% in terms of F1 score and balance the preference of deep detectors for specific types of anomalies. We also study the bias of anomaly types to deep detectors, time-performance trade-offs, shortage of data, and effects of weakly labeled data on both synthetic and realworld datasets to fill out the missing insights in the literature.","PeriodicalId":285763,"journal":{"name":"2023 International Conference on Information Networking (ICOIN)","volume":"53 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 International Conference on Information Networking (ICOIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOIN56518.2023.10049051","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

One critical issue in any network systems is failure detection. Failures not only impact the source network but also propagate through other communicating networks due to the butterfly effect, making root causing of failures even more challenging. Therefore, the necessity to detect failures and anomalies in computer networks is fundamental. Given the nature of computer networks, data is received in a time-series format where each time-point has temporal dependencies on others. As a result, time-series analysis stands out as a potential approach to deal with the task of network anomaly detection. In this paper, we conduct studies on multivariate time series anomaly detection, varying from traditional machine learning techniques to deep learning models. We show that the choice of models is not as important as the choice of pre-processing techniques. Interestingly, non-linear normalization can boost the performance of deep detectors by around 20% in terms of F1 score and balance the preference of deep detectors for specific types of anomalies. We also study the bias of anomaly types to deep detectors, time-performance trade-offs, shortage of data, and effects of weakly labeled data on both synthetic and realworld datasets to fill out the missing insights in the literature.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
计算机网络中时间序列异常检测的评价
任何网络系统中的一个关键问题是故障检测。故障不仅影响源网络,而且由于蝴蝶效应还会通过其他通信网络传播,这使得故障的根本原因更具挑战性。因此,在计算机网络中检测故障和异常是至关重要的。考虑到计算机网络的性质,接收的数据采用时间序列格式,其中每个时间点在时间上依赖于其他时间点。因此,时间序列分析作为处理网络异常检测任务的一种潜在方法脱颖而出。在本文中,我们对多元时间序列异常检测进行了研究,从传统的机器学习技术到深度学习模型。我们表明模型的选择并不像预处理技术的选择那么重要。有趣的是,非线性归一化可以将深度检测器的F1得分提高约20%,并平衡深度检测器对特定类型异常的偏好。我们还研究了异常类型对深度检测器的偏差、时间性能权衡、数据短缺以及弱标记数据对合成和现实数据集的影响,以填补文献中缺失的见解。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Resource Allocation Reinforcement Learning for Quality of Service Maintenance in Cloud-Based Services A Software-Defined Networks Approach for Cyber Physical Systems Resource Allocation and User Association Using Reinforcement Learning via Curriculum in a Wireless Network with High User Mobility Joint Association and Power Allocation for Data Collection in HAP-LEO-Assisted IoT Networks Small Object Detection Technology Using Multi-Modal Data Based on Deep Learning
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1