Method and apparatus for anomaly detection in a network
Abstract:
The disclosure provides a method (100) and apparatus for anomaly detection in a network. The method (100) comprises: obtaining (S110) a stream of time-series data related to the network; and dividing (S120) the stream into a number of sub-streams each corresponding to a category of data. The method further comprises, for each of the sub-streams: reconstructing (S130) a plurality of phase spaces; predicting (S140), in each of the plurality of phase spaces, whether a data item in the sub-stream is an anomaly candidate based on a prediction model associated with the phase space; and detecting (S150) the data item as an anomaly when it is predicted as an anomaly candidate in all of the plurality of phase spaces.
Public/Granted literature
Information query
Patent Agency Ranking
0/0