Anomaly Detection in Partially Observed Traffic Networks
From MaRDI portal
Abstract: This paper addresses the problem of detecting anomalous activity in traffic networks where the network is not directly observed. Given knowledge of what the node-to-node traffic in a network should be, any activity that differs significantly from this baseline would be considered anomalous. We propose a Bayesian hierarchical model for estimating the traffic rates and detecting anomalous changes in the network. The probabilistic nature of the model allows us to perform statistical goodness-of-fit tests to detect significant deviations from a baseline network. We show that due to the more defined structure of the hierarchical Bayesian model, such tests perform well even when the empirical models estimated by the EM algorithm are misspecified. We apply our model to both simulated and real datasets to demonstrate its superior performance over existing alternatives.
Recommendations
Cited in
(4)- Model-based detection of routing events in discrete flow networks
- Network anomaly detection with incomplete audit data
- scientific article; zbMATH DE number 5117355 (Why is no real title available?)
- Optimal volume anomaly detection and isolation in large-scale IP networks using coarse-grained measurements
This page was built for publication: Anomaly Detection in Partially Observed Traffic Networks
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q4628306)