skip to main content
10.1145/2124295.2124388acmconferencesArticle/Chapter ViewAbstractPublication PageswsdmConference Proceedingsconference-collections
abstract

The early bird gets the buzz: detecting anomalies and emerging trends in information networks

Published:08 February 2012Publication History

ABSTRACT

In this work we propose a novel approach to anomaly detection in streaming communication data. We first build a stochastic model for the system based on temporal communication patterns across each edge, which we call the REWARDS (REneWal theory Approach for Real-time Data Streams) model. We then define a measure of anomaly for an arbitrary subgraph based on the likelihood of its recent activity given past behavior. Finally, we develop an algorithm to efficiently identify subgraphs with the most anomalous activity. Although our work has until now focused on the cybersecurity domain, the model we present is more broadly applicable to information retrieval in data streams and information networks.

References

  1. V. Chandola, A. Banerjee, and V. Kumar. Anomaly detection: A survey. ACM Comput. Surv., 41(3), 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. R. E. Tarjan. Efficiency of a good but not linear set union algorithm. J. ACM, 22:215--225, April 1975. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. The early bird gets the buzz: detecting anomalies and emerging trends in information networks

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader