Identifying Novelty in Network Traffic

被引:0
|
作者
Sylvester, Joshua [1 ]
de Lemos, Rogerio [1 ]
机构
[1] Univ Kent, Sch Comp, Canterbury, Kent, England
关键词
D O I
10.1109/CSR61664.2024.10679382
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In a typical Security Operations Centre (SOC), detection methods for malicious transactions are usually resource-intensive, requiring a large team to monitor traffic, which is not ideal for efficient and effective decisions. This paper presents the MAE-NAE FRAMEWORK, consisting of two autoencoders and an adjudicator, which is fast and accurate, but not resource-intensive. One autoencoder is trained on malicious data, while the other is trained on normal data. The adjudicator classifies transactions into malicious, normal or novel, depending on the confidence level. Although autoencoders are widely used for novelty detection, they have not been used to identify novelty in network traffic, which is the key goal of MAE-NAE FRAMEWORK. This allows the provision of a triage system that identifies transactions as novel for which the confidence level in classifying either normal or malicious is low. For evaluating the MAE-NAE FRAMEWORK, we have used the KDDCUP99 benchmark dataset with a simple linear adjudicator. The MAE-NAE FRAMEWORK can classify 94.73% of data as normal or malicious leaving 5.27% of the transactions as novel. We have compared our solution against various solutions within the literature, and the MAE-NAE FRAMEWORK is more effective in classifying transactions.
引用
收藏
页码:506 / 511
页数:6
相关论文
共 50 条
  • [41] Identifying patterns in Internet traffic
    Saifulla, MA
    Murthy, HA
    Gonsalves, TA
    PROCEEDINGS OF THE ICCC 2002: 15TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION, VOLS 1 AND 2: REDEFINING INTERNET IN THE CONTEXT OF PERVASIVE COMPUTING, 2002, : 859 - 865
  • [42] Neural network classification and novelty detection
    Augusteijn, MF
    Folkert, BA
    INTERNATIONAL JOURNAL OF REMOTE SENSING, 2002, 23 (14) : 2891 - 2902
  • [43] Novelty Detection and Analysis with a β-DVAE Network
    Graydon, Tucker
    Sahin, Ferat
    2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2018, : 2687 - 2691
  • [44] Identifying multimodal misinformation leveraging novelty detection and emotion recognition
    Kumari, Rina
    Ashok, Nischal
    Agrawal, Pawan Kumar
    Ghosal, Tirthankar
    Ekbal, Asif
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2023, 61 (03) : 673 - 694
  • [45] IDENTIFYING LEISURE TRAVEL MARKET SEGMENTS BASED ON PREFERENCE FOR NOVELTY
    Weaver, Pamela A.
    McCleary, Ken W.
    Han, Jiho
    Blosser, Phillip E.
    JOURNAL OF TRAVEL & TOURISM MARKETING, 2009, 26 (5-6) : 568 - 584
  • [46] Identifying multimodal misinformation leveraging novelty detection and emotion recognition
    Rina Kumari
    Nischal Ashok
    Pawan Kumar Agrawal
    Tirthankar Ghosal
    Asif Ekbal
    Journal of Intelligent Information Systems, 2023, 61 : 673 - 694
  • [47] Identifying Composition Novelty in Microbiome Studies: Improvement for Prediction Accuracy
    Sun, Yu
    Li, Yanling
    Yuan, Qianqian
    Fu, Xi
    MBIO, 2019, 10 (04):
  • [48] Novelty-based Generalization Evaluation for Traffic Light Detection
    Shekar, Arvind Kumar
    Lake, Laureen
    Gou, Liang
    Ren, Liu
    20TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA 2021), 2021, : 159 - 165
  • [49] Prototype-Based Malware Traffic Classification with Novelty Detection
    Zhao, Lixin
    Cai, Lijun
    Yu, Aimin
    Xu, Zhen
    Meng, Dan
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2019), 2020, 11999 : 3 - 17
  • [50] A complex network analysis approach for identifying air traffic congestion based on independent component analysis
    Jiang, Xurui
    Wen, Xiangxi
    Wu, Minggong
    Song, Min
    Tu, Congliang
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2019, 523 : 364 - 381