Detecting a Variety of Long-Term Stealthy User Behaviors on High Speed Links

Pinghui Wang,Peng Jia,Jing Tao,Xiaohong Guan
DOI: https://doi.org/10.1109/tkde.2018.2873319
IF: 9.235
2019-01-01
IEEE Transactions on Knowledge and Data Engineering
Abstract:Monitoring user behaviors over high speed links is important for applications such as network anomaly detection. Previous work focuses on monitoring anomalies such as extremely frequent users occurring in a short timeslot such as 1 minute. Little attention has been paid to detect users with stealthy behaviors (e.g., persistent, co-occurrence, anti-co-occurrence, and periodic behaviors) over a long period of time at the timeslot granularity. Due to limited computation and storage resources on routers, it is prohibitive to collect massive network traffic in a long period of time. We develop an end-to-end method for solving challenges in both long-term online traffic collection and offline user behavior analysis. We conduct extensive experiments on a variety of real-world traffic to evaluate the performance of detecting persistent, co-occurrence, anti-co-occurrence, and periodic behaviors, and the results demonstrate that our method significantly outperforms state-of-the-art methods.
What problem does this paper attempt to address?