Purdue University
Controlling for confounding network properties in hypothesis testing and anomaly detection
Abstract
dc:description.abstract<p>An important task in network analysis is the detection of anomalous events in a network time series. These events could merely be times of interest in the network timeline or they could be examples of malicious activity or network malfunction. Hypothesis testing using network statistics to summarize the behavior of the network provides a robust framework for the anomaly detection decision process. Unfortunately, choosing network statistics that are dependent on confounding factors like the total number of nodes or edges can lead to incorrect conclusions (e.g., false positives and false negatives). In this dissertation we describe the challenges that face anomaly detection in dynamic network streams regarding confounding factors. We also provide two solutions to avoiding error due to confounding factors: the first is a randomization testing method that controls for confounding factors, and the second is a set of size-consistent network statistics which avoid confounding due to the most common factors, edge count and node count.</p>
Degree
thesis:*- Name thesis:degree_name
- Doctor of Philosophy (PhD)
- Level thesis:degree_level
- Dissertation
- Discipline thesis:degree_discipline
- Computer Science
- Year
- 2016
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Fond, Timothy La
- Contributors dc:contributor
-
- Jennifer Neville
- Daniel Aliaga
- Chris Clifton
- David Gleich
Subjects
dc:subject × 7Identifiers
dc:identifier.*- Repository record dc:identifier
- https://docs.lib.purdue.edu/open_access_dissertations/791
- OAI identifier oai:identifier
- oai:docs.lib.purdue.edu:open_access_dissertations-1983