English
Related papers

Related papers: Catching Unusual Traffic Behavior using TF-IDF-bas…

200 papers

Signature-based and protocol-based intrusion detection systems (IDS) are employed as means to reveal content-based network attacks. Such systems have proven to be effective in identifying known intrusion attempts and exploits but they fail…

Cryptography and Security · Computer Science 2016-08-22 Fabrizio Angiulli , Luciano Argento , Angelo Furfaro

With their widespread popularity, web services have become the main targets of various cyberattacks. Existing traffic anomaly detection approaches focus on flow-level attacks, yet fail to recognize behavior-level attacks, which appear…

Cryptography and Security · Computer Science 2025-11-10 Zhibo Dong , Yong Huang , Shubao Sun , Wentao Cui , Zhihua Wang

Authenticated lateral movement via compromised accounts is a common adversarial maneuver that is challenging to discover with signature- or rules-based intrusion detection systems. In this work a behavior-based approach to detecting…

Cryptography and Security · Computer Science 2021-04-30 Brian A. Powell

With the wide application of IoT and industrial IoT technologies, the network structure is becoming more and more complex, and the traffic scale is growing rapidly, which makes the traditional security protection mechanism face serious…

Computers and Society · Computer Science 2025-04-25 Qiuyan Xiang , Shuang Wu , Dongze Wu , Yuxin Liu , Zhenkai Qin

Anomaly detection through video analysis is of great importance to detect any anomalous vehicle/human behavior at a traffic intersection. While most existing works use neural networks and conventional machine learning methods based on…

Computer Vision and Pattern Recognition · Computer Science 2018-08-31 Mohammmad Farhadi Bajestani , Seyed Soroush Heidari Rahmat Abadi , Seyed Mostafa Derakhshandeh Fard , Roozbeh Khodadadeh

We describe and validate a novel data-driven approach to the real time detection and classification of traffic anomalies based on the identification of atypical fluctuations in the relationship between density and flow. For aggregated data…

Applications · Statistics 2020-12-22 Kieran Kalair , Colm Connaughton

Transport protocols use port numbers to allow connection multiplexing on Internet hosts. TCP as well as UDP, the two most widely used transport protocols, have limitations on what constitutes a valid and invalid port number. One example of…

Networking and Internet Architecture · Computer Science 2020-04-09 Aniss Maghsoudlou , Oliver Gasser , Anja Feldmann

Traffic anomalies and attacks are commonplace in today's networks and identifying them rapidly and accurately is critical for large network operators. For a statistical intrusion detection system (IDS), it is crucial to detect at the…

Graphics · Computer Science 2025-06-27 Pin Ren , Yan Gao , Zhichun Li , Yan Chen , Benjamin Watson

Nowadays, the volume of network traffic continues to grow, along with the frequency and sophistication of attacks. This scenario highlights the need for solutions capable of continuously adapting, since network behavior is dynamic and…

With the rapid development of Internet of Things technologies, the next generation traffic monitoring infrastructures are connected via the web, to aid traffic data collection and intelligent traffic management. One of the most important…

Artificial Intelligence · Computer Science 2023-04-25 Yue Hu , Yuhang Zhang , Yanbing Wang , Daniel Work

Information retrieval systems retrieves relevant documents based on a query submitted by the user. The documents are initially indexed and the words in the documents are assigned weights using a weighting technique called TFIDF which is the…

Information Retrieval · Computer Science 2023-07-13 Kamel Assaf

In recent years, the digitization and automation of anti-financial crime (AFC) investigative processes have faced significant challenges, particularly the need for interpretability of AI model results and the lack of labeled data for…

Computers and Society · Computer Science 2025-04-02 Arthur Capozzi , Salvatore Vilella , Dario Moncalvo , Marco Fornasiero , Valeria Ricci , Silvia Ronchiadin , Giancarlo Ruffo

This paper introduces a novel graph-analytic approach for detecting anomalies in network flow data called GraphPrints. Building on foundational network-mining techniques, our method represents time slices of traffic as a graph, then counts…

Cryptography and Security · Computer Science 2016-02-04 Christopher R. Harshaw , Robert A. Bridges , Michael D. Iannacone , Joel W. Reed , John R. Goodall

Cybersecurity, security monitoring of malicious events in IP traffic, is an important field largely unexplored by statisticians. Computer scientists have made significant contributions in this area using statistical anomaly detection and…

Cryptography and Security · Computer Science 2021-08-23 Ganesh Subramaniam , Huan Chen , Ravi Varadhan , Robert Archibald

IThe botnet is considered as a critical issue of the Internet due to its fast growing mechanism and affect. Recently, Botnets have utilized the DNS and query DNS server just like any legitimate hosts. In this case, it is difficult to…

Networking and Internet Architecture · Computer Science 2009-11-04 Ahmed M. Manasrah , Awsan Hasan , Omar Amer Abouabdalla , Sureswaran Ramadass

This paper explores anomaly detection through temporal network analysis. Unlike many conventional methods, relying on rule-based algorithms or general machine learning approaches, our methodology leverages the evolving structure and…

A method for detecting electronic data theft from computer networks is described, capable of recognizing patterns of remote exfiltration occurring over days to weeks. Normal traffic flow data, in the form of a host's ingress and egress…

Cryptography and Security · Computer Science 2019-11-15 Brian A. Powell

User behaviour analysis based on traffic log in wireless networks can be beneficial to many fields in real life: not only for commercial purposes, but also for improving network service quality and social management. We cluster users into…

Social and Information Networks · Computer Science 2015-11-19 Bingjie Leng , Jingchu Liu , Huimin Pan , Sheng Zhou , Zhisheng Niu

We evaluate methods for applying unsupervised anomaly detection to cybersecurity applications on computer network traffic data, or flow. We borrow from the natural language processing literature and conceptualize flow as a sort of…

Cryptography and Security · Computer Science 2018-05-15 Benjamin J. Radford , Bartley D. Richardson , Shawn E. Davis

This paper addresses the problem of detecting anomalous activity in traffic networks where the network is not directly observed. Given knowledge of what the node-to-node traffic in a network should be, any activity that differs…

Methodology · Statistics 2019-02-20 Elizabeth Hou , Yasin Yilmaz , Alfred Hero