SearcharxivSearch

arXiv · 2408.09788

Simplicial complexes in network intrusion profiling

Abstract

For studying intrusion detection data we consider data points referring to individual IP addresses and their connections: We build networks associated with those data points, such that vertices in a graph are associated via the respective IP addresses, with the key property that attacked data points are part of the structure of the network. More precisely, we propose a novel approach using simplicial complexes to model the desired network and the respective intrusions in terms of simplicial attributes thus generalizing previous graph-based approaches. Adapted network centrality measures related to simplicial complexes yield so-called patterns associated to vertices, which themselves contain a set of features. These are then used to describe the attacked or the attacker vertices, respectively. Comparing this new strategy with classical concepts demonstrates the advantages of the presented approach using simplicial features for detecting and characterizing intrusions.

Explore related subjects

Keep this discovery

BibTeXRIS

Mandala von Westenholz, Martin Atzmueller, Tim Römer. 2024-08-19. Simplicial complexes in network intrusion profiling. https://arxiv.org/abs/2408.09788

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Categories of Multigraded Local Cohomology Modules: Serre Filtrations and Nakayama Duality

Let $\Bbbk$ be a field, let $S=\Bbbk[x_1,\ldots,x_n]$ with its standard $\mathbb N^n$-grading, and let $\mathfrak m=(x_1,\ldots,x_n)$. For $0\le i<n$ and $q=n-i$, we identify the category $\mathcal H_i(\mathbf t)$ of shifted multigraded local cohomology modules with \[ \Rep(U_q(\mathbf t)),\qquad U_q(\mathbf t)=\{\mathbf a\in[\mathbf0,\mathbf t]\mid |\operatorname{supp}(\mathbf a)|\ge q\}. \] This gives the finite and global Serre filtrations and their pure support-rank quotients. We organize the resulting torsion and quotient structures through abelian recollement: an order-ideal decomposition produces a canonical TTF triple, hereditary support torsion pairs, and Gabriel quotients. For finite posets both complementary recollement orientations exist, whereas for the global finite-support categories only the inward-finite orientation is automatic. These recollements admit bounded derived lifts. Under an additional finite-resolution condition the derived finite-support categories have right Serre functors, and derived Kan extensions satisfy a right-Serre exchange. In finite boxes we further construct a functorial rank-layer resolution comparing the left and right Kan sections; Nakayama--Serre duality transforms it into an explicit costandard rank complex. The exceptional top category $\mathcal H_n(\mathbf t)$ is treated separately via second cosyzygies.

math.AC

Associated primes, witnesses, and omega invariants of monomial ideals

We introduce and study the omega invariant of a proper ideal in a Noetherian commutative ring, defined as the number of associated primes of the ideal. Our main objective is to investigate this invariant for monomial ideals and their powers. We characterize associated primes through monomial witnesses and provide an algorithmic procedure for constructing such witnesses from the exponent vectors of the minimal generators. These results lead to explicit formulas and bounds for the omega invariant without requiring the computation of a primary decomposition. We further establish alternative descriptions using irreducible decompositions and Alexander duality. A matrix-based approach is developed to detect associated primes of powers of monomial ideals directly from the exponent matrix of the original ideal. We also investigate the behavior of witnesses under passage from $I^n$ to $I^{n+1}$ and derive corresponding results for edge ideals of graphs.

math.AC

Quadratic Gr\"obner bases for cut ideals of cycles and ring graphs

Let $C_n$ be the cycle of length $n\ge3$ and let $I_{C_n}$ be its cut ideal. We show that $I_{C_n}$ has a quadratic Gr\"obner basis with respect to an explicit weight order. Since the defining configuration consists of $(0,1)$-vectors, the initial monomials of such a basis are automatically squarefree. As the cut polytope of a cycle is the parity polytope, the result gives a regular unimodular flag triangulation of this classical polytope. Together with the known tree case and the clique-sum theorem for cut ideals, the cycle result also yields a quadratic Gr\"obner basis for the cut ideal of every connected ring graph with at least one edge, thereby supplying the missing cycle input and establishing the result for connected ring graphs.

math.AC