A general solution to detect anomalies in networked distributed sensing systems
File(s)
Author(s)
Chen, Po-Yu
Type
Thesis
Abstract
Networked distributed sensing systems (NDSSs) have been widely adopted in many real-world applications which can be either described as cyber-physical system (CPS) or indeed the Internet of Things (IoT). The security and trust in such systems are of paramount importance. In practice, sensor readings may be abnormal or faulty due to various unpredictable causes such as the harsh environments in which they are deployed, the sensors are inherently fault-prone, or they experience malicious attacks. However, although a large body of research has been looking at detecting such anomalies, we have yet seen a common solution that can effectively detect all general anomalies in NDSSs. Many current solutions are either simple but limited by rigid assumptions, or powerful but complex and therefore not suited to resource scarce and large-scale NDSSs. To overcome this problem, we have investigated the causes and patterns of anomaly behaviours in NDSS, and propose a lightweight general solution that can identify most general anomalies in resource-limited NDSSs.
This solution consists of three different components: feature extraction, sensor grouping, and anomaly classification. In feature extraction, we propose two multi-feature dimensionality reduction algorithms, MFDR and MFDR-N. These algorithms extract distinctive time-series features from raw sensor measurements and provide their dimensionality-reduced (DR) representations. In comparison to traditional time-series approaches, MFDR and MFDR-N can provide multiple types of time-series features which can better approximate the original data with smaller error. In addition, to ensure our solution can scale to different sizes of NDSSs while being able to perform sophisticated detection schemes, we propose a distributed matching-based grouping algorithm, DMGA, which clusters sensors into correlation groups where a strong spatiotemporal correlation exists among all sensors. To the best of our knowledge, this grouping
algorithm is the first one to provide performance guarantees in terms of correlation strength. Ultimately, we propose two general anomaly detection classifiers, GAD and FGAD, to capture rapid and gradual pattern changes in sensor measurements, respectively. Both of these are lightweight in terms of computation complexity and can adapt fast to changes in non-stationary environments. Our experimental results show that both GAD and FGAD are very effective against various types of anomalies in real-world NDSS.
This solution consists of three different components: feature extraction, sensor grouping, and anomaly classification. In feature extraction, we propose two multi-feature dimensionality reduction algorithms, MFDR and MFDR-N. These algorithms extract distinctive time-series features from raw sensor measurements and provide their dimensionality-reduced (DR) representations. In comparison to traditional time-series approaches, MFDR and MFDR-N can provide multiple types of time-series features which can better approximate the original data with smaller error. In addition, to ensure our solution can scale to different sizes of NDSSs while being able to perform sophisticated detection schemes, we propose a distributed matching-based grouping algorithm, DMGA, which clusters sensors into correlation groups where a strong spatiotemporal correlation exists among all sensors. To the best of our knowledge, this grouping
algorithm is the first one to provide performance guarantees in terms of correlation strength. Ultimately, we propose two general anomaly detection classifiers, GAD and FGAD, to capture rapid and gradual pattern changes in sensor measurements, respectively. Both of these are lightweight in terms of computation complexity and can adapt fast to changes in non-stationary environments. Our experimental results show that both GAD and FGAD are very effective against various types of anomalies in real-world NDSS.
Version
Open Access
Date Issued
2015-09
Date Awarded
2016-03
Copyright Statement
Attribution NoDerivatives 4.0 International Licence (CC BY-ND)
Advisor
McCann, Julie
Publisher Department
Computing
Publisher Institution
Imperial College London
Qualification Level
Doctoral
Qualification Name
Doctor of Philosophy (PhD)
