在网络安全中对流数据异常检测的调查
1Cyber Science and Engineering, Sichuan University, Chengdu, Sichuan, China.
PeerJ. Computer science
|September 24, 2025
概括
本文审查了用于流数据的网络异常检测算法,以增强网络安全. 它将方法分类并确定未来的研究方向,以快速,高效地检测网络安全操作中的威胁.
科学领域:
- 网络安全和网络安全网络安全.
- 数据科学和机器学习
背景情况:
- 网络异常检测对于识别新型网络威胁至关重要.
- 大规模的数据流对传统的检测方法构成重大挑战.
- 现有的异常检测算法需要对网络安全应用程序进行系统审查.
研究的目的:
- 为网络安全提供最近异常检测算法的全面审查和分析.
- 系统地分类数据集,测量技术,检测算法和数据流的结果.
- 在现实世界的网络安全场景中比较不同方法的能力.
主要方法:
- 对异常检测算法的系统文献综述.
- 数据集的分类,测量技术和检测算法.
- 对算法性能和应用场景的比较分析.
主要成果:
- 详细分类流数据异常检测技术.
- 批判性比较各种算法在网络安全方面的优缺点.
- 确定当前方法中的关键挑战和局限性.
结论:
- 该研究强调了在流媒体网络数据中快速有效地检测异常的必要性.
- 未来的研究应该专注于提高检测准确性和可扩展性.
- 这一综述是推动网络安全研究的宝贵资源.
相关概念视频
Steps in Outbreak Investigation
492
In the ever-evolving field of public health, statistical analysis serves as a cornerstone for understanding and managing disease outbreaks. By leveraging various statistical tools, health professionals can predict potential outbreaks, analyze ongoing situations, and devise effective responses to mitigate impact. For that to happen, there are a few possible stages of the analysis:
492
Unusual Results
3.7K
Unusual results are those that have a very low chance of occurring. Unusual results can be identified using probabilities and the range rule of thumb. In problems involving probability, unusual results can be observed in 2 instances – an unusually high number of successes or an unusually low number of successes.
According to the range rule of thumb, any value above or below two standard deviations, 2σ from the mean, μ is considered unusual.
Maximum unusual value =...
According to the range rule of thumb, any value above or below two standard deviations, 2σ from the mean, μ is considered unusual.
Maximum unusual value =...
3.7K
Random Error
8.3K
Random or indeterminate errors originate from various uncontrollable variables, such as variations in environmental conditions, instrument imperfections, or the inherent variability of the phenomena being measured. Usually, these errors cannot be predicted, estimated, or characterized because their direction and magnitude often vary in magnitude and direction even during consecutive measurements. As a result, they are difficult to eliminate. However, the aggregate effect of these errors can be...
8.3K
Quantifying and Rejecting Outliers: The Grubbs Test
3.5K
Sometimes, a data set can have a recorded numerical observation that greatly deviates from the rest of the data. Assuming that the data is normally distributed, a statistical method called the Grubbs test can be used to determine whether the observation is truly an outlier. To perform a two-tailed Grubbs test, first, calculate the absolute difference between the outlier and the mean. Then, calculate the ratio between this difference and the standard deviation of the sample. This...
3.5K
Detection of Gross Error: The Q Test
6.9K
When one or more data points appear far from the rest of the data, there is a need to determine whether they are outliers and whether they should be eliminated from the data set to ensure an accurate representation of the measured value. In many cases, outliers arise from gross errors (or human errors) and do not accurately reflect the underlying phenomenon. In some cases, however, these apparent outliers reflect true phenomenological differences. In these cases, we can use statistical methods...
6.9K
Interpreting Run Charts
3.0K
Run charts, essentially line graphs plotted over time, serve as fundamental yet effective tools for process analysis. They chronicle data sequentially, facilitating the identification of trends, shifts, or cyclical movements. This graphical representation is instrumental in determining whether a process is stable or exhibits signs of potential instability indicative of special cause variation. In the healthcare domain, run charts depict infection rates over time, enabling hospitals to monitor...
3.0K
