Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Cyber Dynamics I: Finite Macrostates for Behavioral Anomaly Detection in Network Telemetry

About

Entropy-based methods have long been used for network anomaly detection, but most existing approaches treat entropy as a scalar statistic on narrow observables rather than as part of a broader behavioral state-space for cyber systems. We propose a finite-dimensional macrostate framework for network telemetry, instantiated over the Canonical Security Telemetry Substrate (CSTS), so that coarse-graining is performed over persistent entities, typed relations, and temporal state rather than isolated event records. The resulting macrostate captures activity, distributional disorder, structural organization, temporal volatility, persistence, and deviation from benign baselines. Rather than scoring only unusual states, we model window-to-window macrostate transitions and define regime structure, stability, and anomalous change. This supports discrimination between benign workload drift and adversarial reorganization. We evaluate the framework on benchmark network telemetry datasets and compare it against Shannon-, R\'enyi-, and Tsallis-style entropy baselines, as well as standard anomaly detectors. The proposed representation improves anomaly discrimination and supports more interpretable behavioral analysis of cyber telemetry.

Abdul Rahman, Eranga Bandara, Sachin Shetty• 2026

Related benchmarks

TaskDatasetResultRank
Network Anomaly DetectionUNSW-NB15
AUPRC97.3
4
Network Anomaly DetectionCIC-IDS 2017
AUPRC79.17
4
Showing 2 of 2 rows

Other info

Follow for update