{"id":{"repo_id":"cuny-grad","oai_identifier":"oai:academicworks.cuny.edu:gc_etds-6508"},"canonical_url":"https://search.dev.ndltd.org/etd/cuny-grad/oai:academicworks.cuny.edu:gc_etds-6508","repository":{"repo_id":"cuny-grad","name":"City University of New York - Graduate Center","base_url":"https://academicworks.cuny.edu/do/oai/"},"display":{"title":"Structural Anomaly Detection","abstract":"<p>As computer systems become more complex and powerful, the threat of sophisticated and persistent computer attacks increases dramatically. Traditional intrusion detection systems that rely on log analysis struggle to keep pace with these evolving threats, as the attacking trails are often buried in high-volume and high-velocity legitimate activities in the system. Despite tremendous progress in applying machine learning techniques to anomaly-based intrusion detection, such methods continue to suffer from a high false positive rate due to the diversity and variability of individual behavior.To address this problem, this thesis proposes a new framework for detecting structural anomalies in computer systems. The framework is based on the hypothesis that an intruder to a system is motivated by the desire to conduct unwanted or malicious behavior that defies the purpose of the system. When a system is designed for specific purposes, entities in the system driven by certain functionalities act purposely, and interactions among entities are not random, and structures exist. By contrast, malicious behavior will appear out of place with the internal inherited structure a system may have, i.e., structural anomalies.</p> <p>The proposed framework targets detecting functional structures and identifying anomalies related to inherited system functionalities. System functionalities are captured by entity activities in the system, and entity activities are driven by roles they play. As a key element of the framework, the thesis proposes the System Latent Dirichlet Allocation (SysLDA) approach to detect entity roles, assuming that an entity plays multiple roles, and each role represents a set of activities driven by their designated functionalities. The framework is evaluated using a simulated system, and the results demonstrate its capability of detecting structural anomalies. In particular, SysLDA outperforms existing approaches for role detection in the simulated system. The thesis also discusses the challenges and opportunities of the proposed approach and highlights its potential for detecting structural anomalies in computer systems. In summary, this work contributes to the field of anomaly-based intrusion detection by proposing a novel approach that targets detecting functional structures and identifying anomalies related to inherited system functionalities.</p>","abstract_html":"&lt;p&gt;As computer systems become more complex and powerful, the threat of sophisticated and persistent computer attacks increases dramatically. Traditional intrusion detection systems that rely on log analysis struggle to keep pace with these evolving threats, as the attacking trails are often buried in high-volume and high-velocity legitimate activities in the system. Despite tremendous progress in applying machine learning techniques to anomaly-based intrusion detection, such methods continue to suffer from a high false positive rate due to the diversity and variability of individual behavior.To address this problem, this thesis proposes a new framework for detecting structural anomalies in computer systems. The framework is based on the hypothesis that an intruder to a system is motivated by the desire to conduct unwanted or malicious behavior that defies the purpose of the system. When a system is designed for specific purposes, entities in the system driven by certain functionalities act purposely, and interactions among entities are not random, and structures exist. By contrast, malicious behavior will appear out of place with the internal inherited structure a system may have, i.e., structural anomalies.&lt;/p&gt; &lt;p&gt;The proposed framework targets detecting functional structures and identifying anomalies related to inherited system functionalities. System functionalities are captured by entity activities in the system, and entity activities are driven by roles they play. As a key element of the framework, the thesis proposes the System Latent Dirichlet Allocation (SysLDA) approach to detect entity roles, assuming that an entity plays multiple roles, and each role represents a set of activities driven by their designated functionalities. The framework is evaluated using a simulated system, and the results demonstrate its capability of detecting structural anomalies. In particular, SysLDA outperforms existing approaches for role detection in the simulated system. The thesis also discusses the challenges and opportunities of the proposed approach and highlights its potential for detecting structural anomalies in computer systems. In summary, this work contributes to the field of anomaly-based intrusion detection by proposing a novel approach that targets detecting functional structures and identifying anomalies related to inherited system functionalities.&lt;/p&gt;","abstract_has_math":false,"creators":["Luo, Shoufu"],"institution":"The Graduate School and University Center of The City University of New York","degree_name":"Doctor of Philosophy","degree_level":"Doctoral","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Sven Dietrich"],"committee_chairs":[],"committee_members":["Ping Ji","Saptarshi Debroy","Yong Guan"],"year":2023,"date_issued":"2023-06-01T07:00:00Z","date_published":"2023-06-01T07:00:00Z","updated_at":"2026-07-24T01:58:39Z","subjects":["Artificial Intelligence and Robotics","Information Security","Theory and Algorithms","Structural Anomaly","Role Detection","Generative AI","Intrusion Detecrtion"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://academicworks.cuny.edu/gc_etds/5402","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Sven Dietrich"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Ping Ji","Saptarshi Debroy","Yong Guan"]},{"key":"dc:creator","label":"Author","values":["Luo, Shoufu"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2025-06-02T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["The Graduate School and University Center of The City University of New York"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Artificial Intelligence and Robotics","Information Security","Theory and Algorithms","Structural Anomaly","Role Detection","Generative AI","Intrusion Detecrtion"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://academicworks.cuny.edu/gc_etds/5402"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>As computer systems become more complex and powerful, the threat of sophisticated and persistent computer attacks increases dramatically. Traditional intrusion detection systems that rely on log analysis struggle to keep pace with these evolving threats, as the attacking trails are often buried in high-volume and high-velocity legitimate activities in the system. Despite tremendous progress in applying machine learning techniques to anomaly-based intrusion detection, such methods continue to suffer from a high false positive rate due to the diversity and variability of individual behavior.To address this problem, this thesis proposes a new framework for detecting structural anomalies in computer systems. The framework is based on the hypothesis that an intruder to a system is motivated by the desire to conduct unwanted or malicious behavior that defies the purpose of the system. When a system is designed for specific purposes, entities in the system driven by certain functionalities act purposely, and interactions among entities are not random, and structures exist. By contrast, malicious behavior will appear out of place with the internal inherited structure a system may have, i.e., structural anomalies.</p> <p>The proposed framework targets detecting functional structures and identifying anomalies related to inherited system functionalities. System functionalities are captured by entity activities in the system, and entity activities are driven by roles they play. As a key element of the framework, the thesis proposes the System Latent Dirichlet Allocation (SysLDA) approach to detect entity roles, assuming that an entity plays multiple roles, and each role represents a set of activities driven by their designated functionalities. The framework is evaluated using a simulated system, and the results demonstrate its capability of detecting structural anomalies. In particular, SysLDA outperforms existing approaches for role detection in the simulated system. The thesis also discusses the challenges and opportunities of the proposed approach and highlights its potential for detecting structural anomalies in computer systems. In summary, this work contributes to the field of anomaly-based intrusion detection by proposing a novel approach that targets detecting functional structures and identifying anomalies related to inherited system functionalities.</p>"]},{"key":"dc:title","label":"Title","values":["Structural Anomaly Detection"]}]}],"canonical_facts":{"dc:contributor.advisor":["Sven Dietrich"],"dc:contributor.committeemember":["Ping Ji","Saptarshi Debroy","Yong Guan"],"dc:creator":["Luo, Shoufu"],"dc:date.available":["2025-06-02T07:00:00Z"],"dc:description.abstract":["<p>As computer systems become more complex and powerful, the threat of sophisticated and persistent computer attacks increases dramatically. Traditional intrusion detection systems that rely on log analysis struggle to keep pace with these evolving threats, as the attacking trails are often buried in high-volume and high-velocity legitimate activities in the system. Despite tremendous progress in applying machine learning techniques to anomaly-based intrusion detection, such methods continue to suffer from a high false positive rate due to the diversity and variability of individual behavior.To address this problem, this thesis proposes a new framework for detecting structural anomalies in computer systems. The framework is based on the hypothesis that an intruder to a system is motivated by the desire to conduct unwanted or malicious behavior that defies the purpose of the system. When a system is designed for specific purposes, entities in the system driven by certain functionalities act purposely, and interactions among entities are not random, and structures exist. By contrast, malicious behavior will appear out of place with the internal inherited structure a system may have, i.e., structural anomalies.</p> <p>The proposed framework targets detecting functional structures and identifying anomalies related to inherited system functionalities. System functionalities are captured by entity activities in the system, and entity activities are driven by roles they play. As a key element of the framework, the thesis proposes the System Latent Dirichlet Allocation (SysLDA) approach to detect entity roles, assuming that an entity plays multiple roles, and each role represents a set of activities driven by their designated functionalities. The framework is evaluated using a simulated system, and the results demonstrate its capability of detecting structural anomalies. In particular, SysLDA outperforms existing approaches for role detection in the simulated system. The thesis also discusses the challenges and opportunities of the proposed approach and highlights its potential for detecting structural anomalies in computer systems. In summary, this work contributes to the field of anomaly-based intrusion detection by proposing a novel approach that targets detecting functional structures and identifying anomalies related to inherited system functionalities.</p>"],"dc:identifier":["https://academicworks.cuny.edu/gc_etds/5402"],"dc:subject":["Artificial Intelligence and Robotics","Information Security","Theory and Algorithms","Structural Anomaly","Role Detection","Generative AI","Intrusion Detecrtion"],"dc:title":["Structural Anomaly Detection"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Doctoral"],"thesis:degree_name":["Doctor of Philosophy"],"thesis:institution_name":["The Graduate School and University Center of The City University of New York"]},"updated_at":"2026-07-24T01:58:39Z"}