On the Usage of Generative Models for Network Anomaly Detection in Multivariate Time-Series
- 17 May 2021
- journal article
- research article
- Published by Association for Computing Machinery (ACM) in ACM SIGMETRICS Performance Evaluation Review
- Vol. 48 (4), 49-52
- https://doi.org/10.1145/3466826.3466843
Abstract
Despite the many attempts and approaches for anomaly de- tection explored over the years, the automatic detection of rare events in data communication networks remains a com- plex problem. In this paper we introduce Net-GAN, a novel approach to network anomaly detection in time-series, us- ing recurrent neural networks (RNNs) and generative ad- versarial networks (GAN). Different from the state of the art, which traditionally focuses on univariate measurements, Net-GAN detects anomalies in multivariate time-series, ex- ploiting temporal dependencies through RNNs. Net-GAN discovers the underlying distribution of the baseline, multi- variate data, without making any assumptions on its nature, offering a powerful approach to detect anomalies in com- plex, difficult to model network monitoring data. We further exploit the concepts behind generative models to conceive Net-VAE, a complementary approach to Net-GAN for net- work anomaly detection, based on variational auto-encoders (VAE). We evaluate Net-GAN and Net-VAE in different monitoring scenarios, including anomaly detection in IoT sensor data, and intrusion detection in network measure- ments. Generative models represent a promising approach for network anomaly detection, especially when considering the complexity and ever-growing number of time-series to monitor in operational networks.Keywords
This publication has 7 references indexed in Scilit:
- Anomaly-Based Intrusion Detection From Network Flow Features Using Variational AutoencoderIEEE Access, 2020
- A comprehensive survey on machine learning for networking: evolution, applications and research opportunitiesJournal of Internet Services and Applications, 2018
- Online and Scalable Unsupervised Network Anomaly Detection MethodIEEE Transactions on Network and Service Management, 2016
- A Comparative Evaluation of Unsupervised Anomaly Detection Algorithms for Multivariate DataPLOS ONE, 2016
- A survey of network anomaly detection techniquesJournal of Network and Computer Applications, 2016
- Unsupervised Network Intrusion Detection Systems: Detecting the Unknown without KnowledgeComputer Communications, 2012
- Anomaly detectionACM Computing Surveys, 2009