Search arXivSearch

arXiv · 0909.5524

Distributed detection/localization of change-points in high-dimensional network traffic data

Abstract

We propose a novel approach for distributed statistical detection of change-points in high-volume network traffic. We consider more specifically the task of detecting and identifying the targets of Distributed Denial of Service (DDoS) attacks. The proposed algorithm, called DTopRank, performs distributed network anomaly detection by aggregating the partial information gathered in a set of network monitors. In order to address massive data while limiting the communication overhead within the network, the approach combines record filtering at the monitor level and a nonparametric rank test for doubly censored time series at the central decision site. The performance of the DTopRank algorithm is illustrated both on synthetic data as well as from a traffic trace provided by a major Internet service provider.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Alexandre Lung-Yut-Fong, Céline Lévy-Leduc, Olivier Cappé. 2011-09-20. Distributed detection/localization of change-points in high-dimensional network traffic data. https://doi.org/10.1007/s11222-011-9240-5

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Online activity prediction via generalized Indian buffet process models

Online A/B tests are the standard tool for data-driven decision-making at scale. Among the design choices with the largest impact on statistical power is the triggering mechanism: how many users to expose and for how long. This often requires forecasting user engagement, i.e., whether enough users will trigger, and when a target participation level will be reached, from limited pilot data. We introduce a Bayesian nonparametric model for predicting both new-user counts and total triggers, accommodating the heavy-tailed engagement patterns typical of web experiments. All predictive quantities can be computed without intensive numerical procedures such as Markov chain Monte Carlo (MCMC) or variational inference. We evaluate on three public datasets (over 450 public benchmark evaluations) and a proprietary benchmark drawn from 759 production A/B tests comprising 1,774 arms. Across the benchmark analyses, our models are competitive and frequently improve accuracy in forecasting new users, total triggers, and time to reach a target sample size compared with state-of-the-art competitors, especially when only a few pilot days are observed.

stat.AP

Spending Scarce Confirmatory PET Measurements: Target-Aligned Validation in A4/LEARN

Anti-amyloid therapies and blood-based biomarkers are changing Alzheimer disease workups into a two-stage measurement workflow: screen broadly with cheaper information, then spend scarce confirmatory amyloid measurements where they support the decision that will be reported. Amyloid positron-emission tomography (PET) remains one such protocol measurement for amyloid burden, but PET slots, trial budgets, and payer-facing evidence packages are finite. This paper asks a deliberately operational question: when is simple transparent PET validation enough, and when is a fitted residual-uncertainty score worth the added complexity? For a weighted protocol target, the first-order value of validating subject i is the product of target influence and residual protocol uncertainty. Generic uncertainty sampling uses only the second factor and can spend PET measurements on subjects that are hard to predict but weak for the scientific, clinical, or commercial claim. We apply this rule to the A4/LEARN PET archive, treating observed PET as a design laboratory for scarce-confirmation studies. For the primary APOE4 carrier versus non-carrier contrast in Centiloid 24-or-higher PET positivity, simple APOE4-balanced validation recovers nearly all of the target-specific gain: at PET budget 200, the confidence-interval width ratio relative to random validation is 0.923 for APOE4 balancing and 0.914 for target-specific scoring, while generic uncertainty sampling is 0.980. Other targets behave differently: target-specific scoring gives larger gains for an age-slope analysis and for cutoff-indexed PET positivity. The practical message is simple: spend scarce protocol measurements according to the claim being validated, not only according to prediction uncertainty.

stat.AP

Identifying Damage Pathways Linking Sequence Composition to Storage Failure in DNA Data Storage via High-Dimensional Mediation Analysis

DNA data storage offers extraordinary information density and long-term durability, but its reliability is limited by sequence-dependent errors introduced during synthesis and accumulated during storage. It remains unclear how sequence composition is associated with storage failure through specific molecular damage components. We develop a high-dimensional semiparametric mediation framework for survival outcomes. GC content is treated as the exposure, a high-dimensional baseline damage spectrum (a vector of per-read damage counts stratified by trinucleotide context and error type) as the mediator, and storage-quality failure as the outcome. Nonlinear covariate effects in both the mediator and survival models are approximated using deep neural networks. A three-step procedure combining product-of-coefficients screening, Smoothly Clipped Absolute Deviation (SCAD) penalized estimation, and joint significance testing is developed for mediator selection and inference. Applied to an aging experiment on electrochemically synthesized DNA, the method identifies 14 significant mediators, all corresponding to single-base deletions, with estimated mediated effects concentrated in trinucleotide contexts ending in C. These results reveal deletion-type damage as a major pathway linking sequence composition to reduced archival reliability and suggest candidate sequence features for future optimization and error-control strategies. The proposed framework thus offers a mechanism-oriented statistical approach for understanding and improving the reliability of DNA data storage.

stat.AP