Learning Temporal Regularities of User Behavior for Anomaly Detection

  • Authors:
  • Alexandr Seleznyov;Oleksiy Mazhelis;Seppo Puuronen

  • Affiliations:
  • -;-;-

  • Venue:
  • MMM-ACNS '01 Proceedings of the International Workshop on Information Assurance in Computer Networks: Methods, Models, and Architectures for Network Security
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Fast expansion of inexpensive computers and computer networks has dramatically increased number of computer security incidents during last years. While quite many computer systems are still vulnerable to numerous attacks, intrusion detection has become vitally important as a response to constantly increasing number of threats. In this paper we discuss an approach to discover temporal and sequential regularities in user behavior. We present an algorithm that allows creating and maintaining user profiles relying not only on sequential information but taking into account temporal features, such as events' lengths and possible temporal relations between them. The constructed profiles represent peculiarities of users' behavior and used to decide whether a behavior of a certain user is normal or abnormal.