Research article

Lie algebra on weighted function spaces for modeling network anomalies

  • Published: 31 July 2026
  • MSC : 17B65, 46E25

  • The real-time analysis of dynamic and high-dimensional data streams, such as network traffic, raises a number of mathematical and structural difficulties that are not adequately addressed by purely statistical approaches. This study proposes a theoretical framework for anomaly detection based on the construction of topological Lie algebras on weighted spaces of continuous functions. From a mathematical perspective, network states are modeled as elements of a weighted function space $\operatorname{CV}(X, \mathfrak{g})$, where the underlying set $ X $ represents the network domain (for instance, nodes or time indices), the Lie algebra $ \mathfrak{g} $ encodes admissible state transitions, and a Nachbin family of weights $ V $ reflects the nonuniform relevance of different regions of the network. The core contribution of this paper is the identification of a concrete condition on the weight system $ V $, most notably the multiplicative stability condition $ V \leqslant V \cdot V $, which ensures that the pointwise Lie bracket induces a jointly continuous Lie algebra structure on $\operatorname{CV}(X, \mathfrak{g})$. Such an algebraic setting provides a principled mechanism for describing deviations from normal traffic behavior in terms of Lie brackets. In addition, it is shown that the subspace $\operatorname{CV}_0(X, \mathfrak{g})$, corresponding to traffic patterns that vanish at infinity, forms a closed Lie ideal. The closed Lie ideal allows for a natural mathematical distinction between localized anomalies and global, systemwide events. The developed theory is incorporated into an algebraically structured anomaly detection engine (AADE), designed to complement conventional detection techniques by capturing structural aspects of coordinated or evolving attack patterns. The framework provides explicit mathematical characterizations of diverse attack vectors, including distributed denial of service, lateral movement, data exfiltration, and advanced persistent threats, establishing a direct correspondence between algebraic structures and cybersecurity phenomena. As a proof-of-concept validation, experiments on stratified subsets of the NSL-KDD and CIC-IDS-2017 datasets demonstrate that the proposed approach achieves competitive performance compared to both classical machine learning and deep learning baselines. Notably, the algebraic classification mechanism achieves an accuracy of $ 87.4\% $ in distinguishing between localized and systemic threats, with a false localization rate of approximately $ 12\% $. Although the overall detection performance is slightly lower than that of bidirectional long short-term memory (Bi-LSTM) ($ 96.0\% $ vs $ 96.4\% $ F1-score), the approach demonstrates notable strength in detecting sophisticated attack patterns such as low-and-slow exfiltration, achieving a detection rate of $ 68.9\% $ compared to $ 61.8\% $ for Bi-LSTM. The observed performance suggests that the algebraic structure captures complementary structural information in specific scenarios.

    Citation: Hamza Alzaareer, Ahmad M. AL-Diabat. Lie algebra on weighted function spaces for modeling network anomalies[J]. AIMS Mathematics, 2026, 11(7): 23344-23370. doi: 10.3934/math.2026941

    Related Papers:

  • The real-time analysis of dynamic and high-dimensional data streams, such as network traffic, raises a number of mathematical and structural difficulties that are not adequately addressed by purely statistical approaches. This study proposes a theoretical framework for anomaly detection based on the construction of topological Lie algebras on weighted spaces of continuous functions. From a mathematical perspective, network states are modeled as elements of a weighted function space $\operatorname{CV}(X, \mathfrak{g})$, where the underlying set $ X $ represents the network domain (for instance, nodes or time indices), the Lie algebra $ \mathfrak{g} $ encodes admissible state transitions, and a Nachbin family of weights $ V $ reflects the nonuniform relevance of different regions of the network. The core contribution of this paper is the identification of a concrete condition on the weight system $ V $, most notably the multiplicative stability condition $ V \leqslant V \cdot V $, which ensures that the pointwise Lie bracket induces a jointly continuous Lie algebra structure on $\operatorname{CV}(X, \mathfrak{g})$. Such an algebraic setting provides a principled mechanism for describing deviations from normal traffic behavior in terms of Lie brackets. In addition, it is shown that the subspace $\operatorname{CV}_0(X, \mathfrak{g})$, corresponding to traffic patterns that vanish at infinity, forms a closed Lie ideal. The closed Lie ideal allows for a natural mathematical distinction between localized anomalies and global, systemwide events. The developed theory is incorporated into an algebraically structured anomaly detection engine (AADE), designed to complement conventional detection techniques by capturing structural aspects of coordinated or evolving attack patterns. The framework provides explicit mathematical characterizations of diverse attack vectors, including distributed denial of service, lateral movement, data exfiltration, and advanced persistent threats, establishing a direct correspondence between algebraic structures and cybersecurity phenomena. As a proof-of-concept validation, experiments on stratified subsets of the NSL-KDD and CIC-IDS-2017 datasets demonstrate that the proposed approach achieves competitive performance compared to both classical machine learning and deep learning baselines. Notably, the algebraic classification mechanism achieves an accuracy of $ 87.4\% $ in distinguishing between localized and systemic threats, with a false localization rate of approximately $ 12\% $. Although the overall detection performance is slightly lower than that of bidirectional long short-term memory (Bi-LSTM) ($ 96.0\% $ vs $ 96.4\% $ F1-score), the approach demonstrates notable strength in detecting sophisticated attack patterns such as low-and-slow exfiltration, achieving a detection rate of $ 68.9\% $ compared to $ 61.8\% $ for Bi-LSTM. The observed performance suggests that the algebraic structure captures complementary structural information in specific scenarios.



    加载中


    [1] M. Al Lail, A. Garcia, S. Olivo, Machine learning for network intrusion detection—a comparative study, Future Internet, 15 (2023), 243. https://doi.org/10.3390/fi15070243 doi: 10.3390/fi15070243
    [2] S. García, M. Grill, J. Stiborek, A. Zunino, An empirical comparison of botnet detection methods, Comput. Secur., 45 (2014), 100–123. https://doi.org/10.1016/j.cose.2014.05.011 doi: 10.1016/j.cose.2014.05.011
    [3] N. Bourbaki, Lie groups and Lie algebras, Berlin: Springer-Verlag, 1989.
    [4] J. Fuchs, C. Schweigert, Symmetries, Lie algebras and representations: a graduate course for physicists, Cambridge: Cambridge University Press, 2003.
    [5] J. A. de Azcárraga, J. M. Izquierdo, Lie groups, Lie algebras, cohomology and some applications in physics, Cambridge: Cambridge University Press, 1995.
    [6] K. D. Bierstedt, Gewichtete Räume stetiger vektorwertiger Funktionen und das injektive Tensorprodukt, J. Reine Angew. Math., 1973 (1973), 186–210. https://doi.org/10.1515/crll.1973.259.186 doi: 10.1515/crll.1973.259.186
    [7] J. B. Prolla, Weighted spaces of vector-valued continuous functions, Ann. Mat. Pura Appl., 89 (1971), 145–157. https://doi.org/10.1007/BF02414945 doi: 10.1007/BF02414945
    [8] W. H. Summers, The general complex bounded case of the strict weighted approximation problem, Math. Ann., 192 (1971), 90–98. https://doi.org/10.1007/BF02052753 doi: 10.1007/BF02052753
    [9] S. Said, L. Bombrun, Y. Berthoumieu, Warped Riemannian metrics for location-scale models, Cham: Springer, 2019. https://doi.org/10.1007/978-3-030-02520-5_10
    [10] M. Kang, J. Park, J.-Y. Choi, K.-H. Nam, M.-K. Shin, Process algebraic specification of software defined networks, 2012 Fourth International Conference on Computational Intelligence, Communication Systems and Networks, 2012,359–363. https://doi.org/10.1109/CICSyN.2012.72
    [11] P. David, W. Gu, Anomaly detection of time series correlations via a novel Lie group structure, Stat, 11 (2022), e494. https://doi.org/10.1002/sta4.494 doi: 10.1002/sta4.494
    [12] L. Akoglu, H. Tong, D. Koutra, Graph based anomaly detection and description: a survey, Data Min. Knowl. Disc., 29 (2015), 626–688. https://doi.org/10.1007/s10618-014-0365-y doi: 10.1007/s10618-014-0365-y
    [13] X. Wang, N. Pang, Y. Xu, T. Huang, J. Kurths, On state-constrained containment control for nonlinear multiagent systems using event-triggered input, IEEE Trans. Syst. Man Cybern. Syst., 54 (2024), 2530–2538. https://doi.org/10.1109/TSMC.2023.3345365 doi: 10.1109/TSMC.2023.3345365
    [14] X. Wang, W. Guang, T. Huang, J. Kurths, Optimized adaptive finite-time consensus control for stochastic nonlinear multiagent systems with non-affine nonlinear faults, IEEE Trans. Autom. Sci. Eng., 21 (2024), 5012–5023. https://doi.org/10.1109/TASE.2023.3306101 doi: 10.1109/TASE.2023.3306101
    [15] L. Nachbin, Elements of approximation theory, Princeton, N.J.: Van Nostrand, 1967.
    [16] L. Oubbi, Weighted algebras of continuous functions, Results Math. 24 (1993), 298–307. https://doi.org/10.1007/BF03322338
    [17] L. Oubbi, Weighted algebras of vector-valued continuous functions, Math. Nachr., 212 (2000), 117–133.
    [18] M. Tavallaee, E. Bagheri, W. Lu, A. A. Ghorbani, A detailed analysis of the KDD CUP 99 data set, 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, 2009, 1–6. https://doi.org/10.1109/CISDA.2009.5356528
    [19] W. Rudin, Functional analysis, New York: McGraw-Hill, 1991.
    [20] H. Alzaareer, Lie group structures on groups of maps on non-compact spaces and manifolds, Ph.D. thesis, Germany: Paderborn University, 2013.
    [21] H. Alzaareer, Lie groups of $\operatorname{C}^k$-maps on non-compact manifolds and the fundamental theorem for Lie group-valued mappings, J. Group Theory, 24 (2021), 1099–1134. https://doi.org/10.1515/jgth-2018-0200 doi: 10.1515/jgth-2018-0200
  • Reader Comments
  • © 2026 the Author(s), licensee AIMS Press. This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0)
通讯作者: 陈斌, bchen63@163.com
  • 1. 

    沈阳化工大学材料科学与工程学院 沈阳 110142

  1. 本站搜索
  2. 百度学术搜索
  3. 万方数据库搜索
  4. CNKI搜索

Metrics

Article views(295) PDF downloads(24) Cited by(0)

Article outline

Figures and Tables

Tables(10)

Other Articles By Authors

/

DownLoad:  Full-Size Img  PowerPoint
Return
Return

Catalog