We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: A source separation approach to temporal graph modelling for computer networks

Abstract: Detecting malicious activity within an enterprise computer network can be framed as a temporal link prediction task: given a sequence of graphs representing communications between hosts over time, the goal is to predict which edges should--or should not--occur in the future. However, standard temporal link prediction algorithms are ill-suited for computer network monitoring as they do not take account of the peculiar short-term dynamics of computer network activity, which exhibits sharp seasonal variations. In order to build a better model, we propose a source separation-inspired description of computer network activity: at each time step, the observed graph is a mixture of subgraphs representing various sources of activity, and short-term dynamics result from changes in the mixing coefficients. Both qualitative and quantitative experiments demonstrate the validity of our approach.
Subjects: Cryptography and Security (cs.CR); Applications (stat.AP); Machine Learning (stat.ML)
Cite as: arXiv:2303.15950 [cs.CR]
  (or arXiv:2303.15950v1 [cs.CR] for this version)

Submission history

From: Corentin Larroche [view email]
[v1] Tue, 28 Mar 2023 13:07:01 GMT (240kb,D)

Link back to: arXiv, form interface, contact.