Novelty Detection in Network Traffic: Using Survival Analysis for Feature Identification

被引:2
|
作者
Bradley, Taylor [1 ]
Alhajjar, Elie [2 ]
Bastian, Nathaniel D. [2 ]
机构
[1] Johns Hopkins Univ, Whiting Sch Engn, Baltimore, MD 21218 USA
[2] US Mil Acad, Army Cyber Inst, West Point, NY USA
关键词
Novelty detection; network traffic; cyber attacks; machine learning; survival analysis;
D O I
10.1109/ICAA58325.2023.00010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection Systems (NIDS) are an important component of many organizations' cyber defense, resiliency and assurance strategies. However, one downside of these systems is their reliance on known attack signatures for detection of malicious network events. When it comes to unknown attack types and zero-day exploits, even modern machine learning based NIDS often fall short. In this paper, we introduce an unconventional approach to identifying network traffic features that influence novelty detection based on survival analysis techniques. Specifically, we combine several Cox proportional hazards models and implement Kaplan-Meier estimates to predict the probability that a classifier identifies novelty after the injection of an unknown network attack at any given time. The proposed model is successful at pinpointing PSH Flag Count, ACK Flag Count, URG Flag Count, and Down/Up Ratio as the main features to impact novelty detection via Random Forest, Bayesian Ridge, and Linear Support Vector Regression classifiers.
引用
收藏
页码:11 / 18
页数:8
相关论文
共 50 条
  • [1] Analysis of Lightweight Feature Vectors for Attack Detection in Network Traffic
    Meghdouri, Fares
    Zseby, Tanja
    Iglesias, Felix
    APPLIED SCIENCES-BASEL, 2018, 8 (11):
  • [2] Using Object Detection Network for Malware Detection and Identification in Network Traffic Packets
    Du, Chunlai
    Liu, Shenghui
    Si, Lei
    Guo, Yanhui
    Jin, Tong
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 64 (03): : 1785 - 1796
  • [3] Novelty Detection and Analysis with a β-DVAE Network
    Graydon, Tucker
    Sahin, Ferat
    2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2018, : 2687 - 2691
  • [4] THE EFFICIENCY ANALYSIS OF THE STATISTICAL FEATURE IN NETWORK TRAFFIC IDENTIFICATION BASED ON BP NEURAL NETWORK
    Mu, Cheng
    Zhang, Changzhi
    Huang, Xiaohong
    Ma, Yan
    2013 5TH IEEE INTERNATIONAL CONFERENCE ON BROADBAND NETWORK & MULTIMEDIA TECHNOLOGY (IC-BNMT), 2013, : 70 - 74
  • [5] Accurate compressed traffic detection via traffic analysis using Graph Convolutional Network based on graph structure feature
    Fu, Nan
    Cheng, Guang
    Su, Xinyue
    COMPUTER COMMUNICATIONS, 2023, 207 : 128 - 139
  • [6] Effectiveness of feature extraction in neural network architectures for novelty detection
    Addison, JFD
    Wermter, S
    MacIntyre, J
    NINTH INTERNATIONAL CONFERENCE ON ARTIFICIAL NEURAL NETWORKS (ICANN99), VOLS 1 AND 2, 1999, (470): : 976 - 981
  • [7] Traffic Sign Detection and Classification using Colour Feature and Neural Network
    Sheikh, Md. Abdul Alim
    Kole, Alok
    Maity, Tanmoy
    2016 INTERNATIONAL CONFERENCE ON INTELLIGENT CONTROL POWER AND INSTRUMENTATION (ICICPI), 2016, : 307 - 311
  • [8] Identifying Novelty in Network Traffic
    Sylvester, Joshua
    de Lemos, Rogerio
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 506 - 511
  • [9] Integrated Feature Pyramid Network With Feature Aggregation for Traffic Sign Detection
    Tang, Qing
    Cao, Ge
    Jo, Kang-Hyun
    IEEE ACCESS, 2021, 9 : 117784 - 117794
  • [10] Network Intrusion Traffic Detection Based on Feature Extraction
    Yu, Xuecheng
    Huang, Yan
    Zhang, Yu
    Song, Mingyang
    Jia, Zhenhong
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 78 (01): : 473 - 492