Anomaly detection of user behavior based on DTMC with states of variable-length sequences

来源 :The Journal of China Universities of Posts and Telecommunica | 被引量 : 0次 | 上传用户:carina52
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
In anomaly detection,a challenge is how to model a user’s dynamic behavior.Many previous works represent the user behavior based on fixed-length models.To overcome their shortcoming,we propose a novel method based on discrete-time Markov chains(DTMC) with states of variable-length sequences.The method firstly generates multiple shell command streams of different lengths and combines them into the library of general sequences.Then the states are defined according to variable-length behavioral patterns of a valid user,which improves the precision and adaptability of user profiling.Subsequently the transition probability matrix is created.In order to reduce computational complexity,the classification values are determined only by the transition probabilities,then smoothed with sliding windows,and finally used to discriminate between normal and abnormal behavior.Two empirical evaluations on datasets from Purdue University and AT&T Shannon Lab show that the proposed method can achieve higher detection accuracy and require less memory than the other traditional methods. In anomaly detection, a challenge is how to model a user’s dynamic behavior. Many previous works represent the user behavior based on fixed-length models. To overcome their shortcoming, we propose a novel method based on discrete-time Markov chains (DTMC) with states of variable-length sequences. The method previously generated multiple shell command streams of different lengths and combines them into the library of general sequences.. the the states are defined according to variable-length behavioral patterns of a valid user, which improves the precision and adaptability of user profiling.Subsequently the transition probability matrix is ​​created.In order to reduce computational complexity, the classification values ​​are determined only by the transition probabilities, then smoothed with sliding windows, and finally used to discriminate between normal and abnormal behavior. Two empirical evaluations on datasets from Purdue University and AT & T Shannon Lab show that the proposed method can achieve highe r detection accuracy and require less memory than the other traditional methods.
其他文献
瑞典皇家科学院于2014年10月7日揭晓了2014年诺贝尔物理学奖获得者,这一奖项被授予日本科学家赤崎勇、天野浩和美籍日裔科学家中村修二,以表彰他们在20世纪90年代初发明了蓝
最近,杭州香凯信息技术有限公司、上海昊来信息技术有限公司与其他两家企业广州科宸电脑工程有限公司、广州华濠数码科技有限公司成为首批“思杰专家”认证合作伙伴。在IT服
本研究通过分析磁共振弥散张量成像(diffusion tensor imaging,DTI)数据,观察内侧颞叶癫痫(mesial temporal lobe epilepsy,mTLE)患者大脑白质的改变。46例伴有单侧海马硬化
目的:对医药成人教育的学员学习动机的研究探讨。方法:本文通过编制成人学习动机量表,对江门中医药成人教育的学员参与学习活动的动机取向及其相关因素进行分析。结果与结论:
标点符号的使用条条框框多,层次繁复,靠死记硬背,不仅费时费力,且未必见效。因此,我们在复习时不必面面俱到,就一些容易错用、混用的标点作一番比较分析,熟悉标点符号使用中
2015年5月19日至31日,资深教育媒体人沈祖芸飞越太平洋赴美国三座城市(哥伦布、纽约、勒星顿)参访6所中学(哥汉娜林肯高中、布朗克斯高中、石溪中学、霍勒斯格瑞利高中、哈克
摘 要:职业指导发源于美国,传入我国也有百年的历史,在这一时期,我国职业指导工作经历了从萌芽到繁荣的阶段,逐渐形成了符合我国国情的职业指导理论体系。本文旨在对我国职业指导的发展历程进行梳理,以期给我国职业指导工作者以帮助和启示。  关键词:职业指导;发展;历史  DOI:10.19354/j.cnki.42-1616/f.2016.17.74  职业指导诞生于1908年,由美国波士顿教授帕森斯提出
大庆油田技能人才评价组织制定了严格的工作程序与规范,并对实施评价质量督导的程序与标准进行了设计与优化,形成了适合大庆油田技能人才评价特点的督导工作程序与规范。一、
◎《高中生之友》编辑部鼎力策划◎全国名家名师名校联合打造◎2009年5月倾情奉献(两专刊均16开,96页,定价7.60元)《高考前台》专刊《美文鉴赏》专刊《高中生之友》高考版200
读书的人生最美丽,让书籍成为人类的好朋友,让学习成为一种习惯,曾是不少文坛先辈、大家一再呼吁的事。可是,近年来,随着网络及信息化程度的提高,以及阅读功利化倾向的日趋严