We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.SI

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Statistics > Methodology

Title: Anomaly Detection in Large Scale Networks with Latent Space Models

Abstract: We develop a real-time anomaly detection algorithm for directed activity on large, sparse networks. We model the propensity for future activity using a dynamic logistic model with interaction terms for sender- and receiver-specific latent factors in addition to sender- and receiver-specific popularity scores; deviations from this underlying model constitute potential anomalies. Latent nodal attributes are estimated via a variational Bayesian approach and may change over time, representing natural shifts in network activity. Estimation is augmented with a case-control approximation to take advantage of the sparsity of the network and reduces computational complexity from $O(N^2)$ to $O(E)$, where $N$ is the number of nodes and $E$ is the number of observed edges. We run our algorithm on network event records collected from an enterprise network of over 25,000 computers and are able to identify a red team attack with half the detection rate required of the model without latent interaction terms.
Subjects: Methodology (stat.ME); Cryptography and Security (cs.CR); Social and Information Networks (cs.SI); Applications (stat.AP); Machine Learning (stat.ML)
Cite as: arXiv:1911.05522 [stat.ME]
  (or arXiv:1911.05522v2 [stat.ME] for this version)

Submission history

From: Tyler McCormick [view email]
[v1] Wed, 13 Nov 2019 14:57:20 GMT (143kb,D)
[v2] Fri, 29 Jan 2021 18:20:46 GMT (607kb,D)

Link back to: arXiv, form interface, contact.