|
|
|
|
|
by shivin9
2326 days ago
|
|
Impressive results! Few questions though:- 1) Do you use sliding window approach or exponential decay? 2) When you say groups of similar edges, do they have to be spatially close to each other? or can they be equally distributed in the graph? 3) Can an attacker figure out the optimum time difference between his attacks such that MIDAS doesn't detect it as an anomaly? The time gap is just sufficient enough for the algorithm to weed out the potentially malicious micro-cluster as obsolete. Seems like an interesting extension to your work. Best of luck! |
|