Distributed network threat events are characterized by large scale and wide coverage, and seriously threaten the stable operation of data communication networks. Therefore, achieving early detection of distributed network events (DNEs) has been one of the major challenges faced by global network operators. Recently, due to the enhanced utilization of victim contextual information in event detection, graph anomaly detection methods have garnered widespread attention for their superior performance in event detection compared to traditional single-point methods. However, these methods usually only focus on local anomalies and have difficulties in fully exploiting the interconnected nature of networks for the early detection of DNEs. To overcome these limitations, in this study we detect DNEs by exploiting the spatiotemporal morphology in the forwarding behavior of the network during their propagation. The proposed approach uses a novel Hidden Markov Random Field (HMRF) to characterize the temporal variations in the transmission behavior of the network. In order to comprehensively delineate the differences in the impact among hidden states, this model employs both Continuous Bag of Words (CBOW) and a potential model with dynamic weights. These components are utilized to characterize the relationships between the hidden states of network entities and links and their spatiotemporal neighbors. To adapt to the statistical distributions of traffic in different scenarios, a Deep Neural Network (DNN) is used to represent the probabilistic relationships between each hidden state and its associated traffic features. By using this model, it is possible to calculate the current hidden state field of the target network. The early detection of events is achieved based on the spatiotemporal morphology of the hidden state field and its correlation with DNEs. The experimental results demonstrate that our proposed framework outperforms the existing baseline methods in real datasets and diverse network event scenarios.
No takes yet. Share an insight, caveat, or question.
Xiao et al. (2024) studied this question.
Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context: