In plain words: A streaming checker that watches records with several attributes—both labels and numbers—and flags odd groups as they arrive, tracking how the attributes relate. It processes each record in constant time and memory, and outperformed the best existing detectors on four network-attack datasets.
Abstract · MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams
Given a stream of entries in a multi-aspect data setting i.e., entries having multiple dimensions, how can we detect anomalous activities in an unsupervised manner? For example, in the intrusion detection setting, existing work seeks to detect anomalous events or edges in dynamic graph streams, but this does not allow us to take into account additional attributes of each entry. Our work aims to define a streaming multi-aspect data anomaly detection framework, termed MSTREAM which can detect unusual group anomalies as they occur, in a dynamic manner. MSTREAM has the following properties: (a) it detects anomalies in multi-aspect data including both categorical and numeric attributes; (b) it is online, thus processing each record in constant time and constant memory; (c) it can capture the correlation between multiple aspects of the data. MSTREAM is evaluated over the KDDCUP99, CICIDS-DoS, UNSW-NB 15 and CICIDS-DDoS datasets, and outperforms state-of-the-art baselines.
Siddharth Bhatia, Arjit Jain, Pan Li, Ritesh Kumar, Bryan Hooi
arXiv:2009.08451 · cs.LG, cs.AI, stat.ML · submitted Sep 17, 2020 · updated Mar 30, 2021
abstract · pdf · html · The Web Conference (WWW), 2021
Github Repository: https://github.com/Stream-AD/MStream