The increasing number of workflow systems in recent years have realized the necessity of anomaly detection in order to keep their systems secure and intact. In this paper, we provide an in-depth comparative review of uADR and sADR. This research measures how well both approaches are effective or efficient across a broad range of workflow contexts. In the case of the supervised methods, they use labelled datasets in order to detect differences from known patterns and they compensate a lot for stable situations to the point that the staying error tends to be low. On the other hand, unsupervised methods identify anomalies without having any prior information of the normal behaviour, which makes it more flexible in dynamic and evolving environments. Our performance analysis covers different metrics like detection accuracy, computational load, versatility, and false positive rates. This special section contributes an array of experimental results and in-depth case studies, illustrating what each sADR and uADR approach can and cannot do. The performance comparison of certain anomaly detection methods and an extensive list of factors to consider when choosing an appropriate anomaly detection (based on workflow mapping) provide valuable information not available elsewhere to data scalers and researchers. The objective of this study is to support developers and researchers in choosing the right method to make their workflow systems robust, reliable, and secure based on provided information.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CASUAD-WR: A Comparative Analysis of Supervised and Unsupervised Anomaly Detection in Workflow Relations: Methodologies and Performance Metrics

  • Arun Kumar Bandlamudi,
  • Sunitha Pachala

摘要

The increasing number of workflow systems in recent years have realized the necessity of anomaly detection in order to keep their systems secure and intact. In this paper, we provide an in-depth comparative review of uADR and sADR. This research measures how well both approaches are effective or efficient across a broad range of workflow contexts. In the case of the supervised methods, they use labelled datasets in order to detect differences from known patterns and they compensate a lot for stable situations to the point that the staying error tends to be low. On the other hand, unsupervised methods identify anomalies without having any prior information of the normal behaviour, which makes it more flexible in dynamic and evolving environments. Our performance analysis covers different metrics like detection accuracy, computational load, versatility, and false positive rates. This special section contributes an array of experimental results and in-depth case studies, illustrating what each sADR and uADR approach can and cannot do. The performance comparison of certain anomaly detection methods and an extensive list of factors to consider when choosing an appropriate anomaly detection (based on workflow mapping) provide valuable information not available elsewhere to data scalers and researchers. The objective of this study is to support developers and researchers in choosing the right method to make their workflow systems robust, reliable, and secure based on provided information.