Score-Based Unsupervised Anomaly Detection using Graph Clustering and the Activity and Event Network Model
Amir Mohammadi Bagha, Isaac Woungang, Issa Traoré · 2023
Developing a real-time unsupervised anomaly detection system that is able to detect a broad range of attacks, including insider threats, distributed denial-of-service attacks, and Advanced Persistent Threats, among others, in real-time, is still a challenge. In this paper, a new anomaly detection scheme is proposed, which is based on the Activity and Event Network (AEN) framework, a new knowledge graph model that allows capturing the dynamicity and uncertainty inherent in network activities while providing a foundation for expressing various threat detection approaches. The considered unsupervised learning-based approach takes advantage of node clustering in the network to establish a normal behaviour for each cluster and detect the anomalies accordingly. Our proposed scheme is evaluated using the CIC 2018 IDS dataset, yielding a false positive rate (FPR) of 0.83% and a detection rate (DR) of 79%.