Automatic signature generation for anomaly detection in business process instance data

Kristof Böhmer, Stefanie Rinderle-Ma

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Scopus citations

Abstract

Implementing and automating business processes often means to connect and integrate a diverse set of potentially flawed services and applications. This makes them an attractive target for attackers. Here anomaly detection is one of the last defense lines against unknown vulnerabilities. Whereas anomaly detection for process behavior has been researched, anomalies in process instance data have been neglected so far, even though the data is exchanged with external services and hence might be a major sources for attacks. Deriving the required anomaly detection signatures can be a complex, work intensive, and error-prone task, specifically at the presence of a multitude of process versions and instances. Hence, this paper proposes a novel automatic signature generation approach for textual business process instance data while respecting its contextual attributes. Its efficiency is shown by an comprehensive evaluation that applies the approach on thousands of realistic data entries and 240, 000 anomalous data entries.

Original languageEnglish
Title of host publicationEnterprise, Business-Process and Information Systems Modeling - 17th International Conference, BPMDS 2016, 21st International Conference, EMMSAD 2016, Held at CAiSE 2016, Proceedings
EditorsRainer Schmidt, Ilia Bider, Sérgio Guerreiro, Wided Guédria
PublisherSpringer Verlag
Pages196-211
Number of pages16
ISBN (Print)9783319394282
DOIs
StatePublished - 2016
Externally publishedYes
Event17th International Conference on Business Process Modeling, Development and Support, BPMDS 2016 and 21st International Conference on Exploring Modeling Methods for Systems Analysis and Design, EMMSAD 2016 held at Conference on Advanced Information Systems Engineering, CAiSE 2016 - Ljubljana, Slovenia
Duration: 13 Jun 201614 Jun 2016

Publication series

NameLecture Notes in Business Information Processing
Volume248
ISSN (Print)1865-1348

Conference

Conference17th International Conference on Business Process Modeling, Development and Support, BPMDS 2016 and 21st International Conference on Exploring Modeling Methods for Systems Analysis and Design, EMMSAD 2016 held at Conference on Advanced Information Systems Engineering, CAiSE 2016
Country/TerritorySlovenia
CityLjubljana
Period13/06/1614/06/16

Keywords

  • Anomaly detection
  • Process instance
  • Regex
  • Textual data

Fingerprint

Dive into the research topics of 'Automatic signature generation for anomaly detection in business process instance data'. Together they form a unique fingerprint.

Cite this