Skip to main content
QUICK REVIEW

[论文解读] Anomaly Detection in Business Process Runtime Behavior -- Challenges and Limitations

Kristof Böhmer, Stefanie Rinderle‐Ma|arXiv (Cornell University)|May 18, 2017
Network Security and Intrusion Detection被引用 10
一句话总结

本篇系统文献综述识别并分析了35项关于业务流程运行时行为异常检测的研究,揭示了关键局限性,如过度依赖点异常、忽视集体异常和上下文异常,以及对演化过程模型支持不足。该研究提出了未来研究方向,以实现对复杂、多实例攻击和数据流异常的检测。

ABSTRACT

Anomaly detection is generally acknowledged as an important problem that has already drawn attention to various domains and research areas, such as, network security. For such "classic" application domains a wide range of surveys and literature reviews exist already - which is not the case for the process domain. Hence, this systematic literature review strives to provide an organized holistic view on research related to business process runtime behavior anomaly detection. For this the unique challenges of the process domain are outlined along with the nature of the analyzed data and data sources. Moreover, existing work is identified and categorized based on the underlying fundamental technology applied by each work. Furthermore, this work describes advantages and disadvantages of each identified approach. Based on these information limitations and gaps in existing research are identified and recommendations are proposed to tackle them. This work aims to foster the understanding and development of the process anomaly detection domain.

研究动机与目标

  • 为业务流程运行时行为异常检测研究提供全面、系统的概述。
  • 基于底层技术与方法,识别并分类现有方法。
  • 在流程特定挑战的背景下,分析每种方法的优势与劣势。
  • 揭示当前研究在演化流程和复杂异常方面的研究空白与局限性。
  • 提出未来研究方向,以实现业务流程中更稳健、更全面的异常检测。

提出的方法

  • 采用既定的学术综述指南,开展系统文献综述。
  • 通过聚焦于标题、摘要和关键词的关键词,在主要研究数据库中进行检索。
  • 基于与业务流程运行时行为异常检测的相关性,筛选并分析35篇相关出版物。
  • 根据底层技术对方法进行分类,并评估其优缺点。
  • 识别出诸如灵活流程模型、定义演变以及集体异常和上下文异常代表性不足等挑战。
  • 采用滚雪球法和多数据库检索策略,确保全面覆盖,仅排除非电子或人工整理的来源。

实验结果

研究问题

  • RQ1与其它领域相比,业务流程运行时行为异常检测面临哪些独特挑战?
  • RQ2在流程领域中,哪些异常检测技术被主要使用,它们在有效性与覆盖范围方面如何比较?
  • RQ3当前方法在演化流程和复杂攻击模式方面存在哪些关键局限性与研究空白?
  • RQ4现有方法如何处理集体异常和上下文异常,其对安全性的含义是什么?
  • RQ5为提升对复杂、多实例攻击的检测能力,需要哪些未来研究方向?

主要发现

  • 流程异常检测领域主要依赖点异常,导致集体异常和上下文异常在很大程度上未被检测到。
  • 技术使用存在显著失衡,尽管其他领域提供了多样化的技术方法,但仅有少数方法占据主导地位。
  • 现有方法难以应对演化和灵活的流程模型,而这是现实世界业务流程的核心特征。
  • 许多研究未能检测出恶意意图被拆分到多个流程实例中的攻击,每个实例单独看均表现正常。
  • 缺乏真实世界、公开可获取的流程行为数据,尤其是带有标注异常的数据,严重阻碍了方法的验证与基准测试。
  • 监管框架如GDPR和HIPAA强调了更强异常检测的必要性,但当前解决方案在满足合规性与安全需求方面仍显不足。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。