vix.ing · top · new · best · stats · spec

A Model-Based Approach to Anomaly Detection Trading Detection Time and\n False Alarm Rate

2020/06/15 by Charles F. Gonçalves, Gonçalves, Charles F., Daniel Sadoc Menasché +7
Computer Science · #Anomaly Detection Techniques and Applications #C.4 #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Network Security and Intrusion Detection #Software Engineering (cs.SE) #Software System Performance and Reliability

paper · pdf · doi:10.48550/arxiv.2006.08811

openalex publication_date 2020/06/15 · openalex created_date 2022/07/23 · openalex updated_date 2026/08/01

Abstract

The complexity and ubiquity of modern computing systems is a fertile ground\nfor anomalies, including security and privacy breaches. In this paper, we\npropose a new methodology that addresses the practical challenges to implement\nanomaly detection approaches. Specifically, it is challenging to define normal\nbehavior comprehensively and to acquire data on anomalies in diverse cloud\nenvironments. To tackle those challenges, we focus on anomaly detection\napproaches based on system performance signatures. In particular, performance\nsignatures have the potential of detecting zero-day attacks, as those\napproaches are based on detecting performance deviations and do not require\ndetailed knowledge of attack history. The proposed methodology leverages an\nanalytical performance model and experimentation and allows to control the rate\nof false positives in a principled manner. The methodology is evaluated using\nthe TPCx-V workload, which was profiled during a set of executions using\nresource exhaustion anomalies that emulate the effects of anomalies affecting\nsystem performance. The proposed approach was able to successfully detect the\nanomalies, with a low number of false positives (precision 90%-98%).\n

Related