0% Complete
English
صفحه اصلی
/
شانزدهمین کنفرانس بین المللی فناوری اطلاعات و دانش
Kalman Filter–Based Anomaly Detection for User Authentication Failures in Enterprise Logs
نویسندگان :
Somayeh Soltani
1
Hossein Nikdel
2
1- دانشگاه تربت حیدریه
2- دانشگاه صنعتی شاهرود
کلمات کلیدی :
Anomaly detection،Brute-force attack،Time-series prediction،Kalman filter،Login failure
چکیده :
User authentication failures sometimes indicate malicious attempts such as brute-force or credential-stuffing. Unfortunately, simplistic threshold-based alarms yield high false-positive rates in dynamic enterprise environments. This paper presents a systematic study of Kalman filter–based anomaly detection applied to a 60-day real-world audit-log dataset. It compares four variants of the filter—simple Local Level (LL), Local Level with Trend (LLT), Local Level with Seasonal component (LLS), and Local Level with both Trend and Seasonal components (LLTS)—across multiple time-aggregation windows (1, 2, 8, and 24 hours). Each configuration is assessed using three complementary metrics: outlier count (detection sensitivity), coefficient of determination (R²), and root-mean-squared error (RMSE). Experimental results show that the LL variant with a 2-hour window achieves the best trade-off, yielding R² = 0.9894, RMSE = 5.97, and no detected outliers (i.e., zero false positives).
لیست مقالات
لیست مقالات بایگانی شده
An Attention-Enhanced Hybrid Deep Learning Framework for Detecting Denial-of-Wallet Attacks in Serverless Platforms
Mohammad Mehmandoost - HadiShahriar Shahhoseini
Mode Selection and Resource Allocation in D2D-Enabled MC-NOMA using Matching Theory
Alireza Gholamrezaee - Hamid Farrokhi - Javad Zeraatkar Moghaddam
طراحی واسط کاربری مبتنی بر رفتار و احساسات کاربران در سیستم های هوشمند
فاطمه صبائی - دکتر احمد عبداله زاده بارفروش
A Comparison between Slimed Network and Pruned Network for Head Pose Estimation
Amir Salimiparsa - Hadi Veisi - Mohammad-shahram Moin
Architectural Insights: Comparing Weight Stationary and Output Stationary Systolic Arrays for Efficient Computation
Mahdi Kalbasi
Statistical distance-base acceptance strategy for desirable offers in bilateral automated negotiation
Arash Ebrahimnezhad - Dr Hamid Jazayeriy - Dr Faria Nassiri-mofakham
Improving Privacy Protection in a Collaborative Blockchain-based E-Health Records System
Arman Emam-Hoseini - Samane Sobuti - دکتر سیاوش خرسندی - Alireza Hashemi-Golpayeghani
Automatic Analysis of Inconsistencies in Inter-Enterprise Business Processes: Introducing a Formal Adaptation Patterns Catalog
Somayeh Ashourian - Shohreh َAjoudanian
مدیریت دانش هوشمند مبتنی بر بازیابی-تولید افزوده شده : معماری، ارزیابی و حاکمیت برای دستیار دانش سازمانی
محمدهادی صفری نادری
Data Analysis to Reduce Electrical Power Plants
Amirali Sahraei - Jamshid Shanbehzadeh
بیشتر
ثمین همایش، سامانه مدیریت کنفرانس ها و جشنواره ها - نگارش 43.8.0