Detecting Periodic Subsequences in Cyber Security Data
Turcotte, Melissa [Los Alamos National Lab. (LANL), Los Alamos, NM (United States)]; Price-Williams, Matthew James [Los Alamos National Lab. (LANL), Los Alamos, NM (United States); Imperial College, London (United Kingdom)]; Heard, Nick [Imperial College, London (United Kingdom); Bristol Univ. (United Kingdom)] · OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information) · 2021
Anomaly detection for cyber-security defence has garnered much attention in recent years providing an orthogonal approach to traditional signature-based detection systems. Anomaly detection relies on building probability models ofnormal computer network behaviour and detecting deviations from the model. Most data sets used for cyber-security have a mix of user-driven events and automated network events, which most often appears as polling behaviour. Separating these automated events from those caused by human activity is essential to building good statistical models for anomaly detection. In this article, we present a change point detection framework for identifying automated network events appearing as periodic subsequences of event times. The opening event of each subsequence is interpreted as a human action which then generates an automated, periodic process. Difficulties arising from the presence of duplicate and missing data are addressed. The methodology is demonstrated using authentication data from Los Alamos National Laboratory's enterprise computer network.