Novelty Detection in Network Traffic: Using Survival Analysis for Feature Identification

被引:2
|
作者
Bradley, Taylor [1 ]
Alhajjar, Elie [2 ]
Bastian, Nathaniel D. [2 ]
机构
[1] Johns Hopkins Univ, Whiting Sch Engn, Baltimore, MD 21218 USA
[2] US Mil Acad, Army Cyber Inst, West Point, NY USA
关键词
Novelty detection; network traffic; cyber attacks; machine learning; survival analysis;
D O I
10.1109/ICAA58325.2023.00010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection Systems (NIDS) are an important component of many organizations' cyber defense, resiliency and assurance strategies. However, one downside of these systems is their reliance on known attack signatures for detection of malicious network events. When it comes to unknown attack types and zero-day exploits, even modern machine learning based NIDS often fall short. In this paper, we introduce an unconventional approach to identifying network traffic features that influence novelty detection based on survival analysis techniques. Specifically, we combine several Cox proportional hazards models and implement Kaplan-Meier estimates to predict the probability that a classifier identifies novelty after the injection of an unknown network attack at any given time. The proposed model is successful at pinpointing PSH Flag Count, ACK Flag Count, URG Flag Count, and Down/Up Ratio as the main features to impact novelty detection via Random Forest, Bayesian Ridge, and Linear Support Vector Regression classifiers.
引用
收藏
页码:11 / 18
页数:8
相关论文
共 50 条
  • [21] In-Network ML Feature Computation for Malicious Traffic Detection
    Amado, Joao R.
    Pereira, Francisco
    Signorello, Salvatore
    Correia, Miguel
    Ramos, Fernando M. V.
    PROCEEDINGS OF THE 2023 ACM SIGCOMM 2023 CONFERENCE, SIGCOMM 2023, 2023, : 1105 - 1107
  • [22] Automated Feature Selection for Anomaly Detection in Network Traffic Data
    Nakashima, Makiya
    Sim, Alex
    Kim, Youngsoo
    Kim, Jonghyun
    Kim, Jinoh
    ACM TRANSACTIONS ON MANAGEMENT INFORMATION SYSTEMS, 2021, 12 (03)
  • [23] An optimized feature extraction algorithm for abnormal network traffic detection
    Chen, Jinfu
    Chen, Yuhao
    Cai, Saihua
    Yin, Shang
    Zhao, Lingling
    Zhang, Zikang
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 149 : 330 - 342
  • [24] Attention feature fusion network for small traffic sign detection
    Wu, Miaozhi
    Yang, Jingmin
    Zhang, Wenjie
    Zheng, Yifeng
    Liao, Jianxin
    ENGINEERING RESEARCH EXPRESS, 2022, 4 (03):
  • [25] Probable Biomarker Identification using Recursive Feature Extraction and Network Analysis
    Mishra, Arpit
    Gupta, Abhishek
    Maheswari, Umesh
    Siddique, Laeeq
    2017 17TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW 2017), 2017, : 470 - 477
  • [26] Analysis and Detection of Anomalous Network Traffic
    Jeong, Hae-Duck J.
    Kim, Hyeonggeun
    Ahn, WonHwi
    Oh, Jung-hee
    Lee, Dawoon
    Ye, Sang-Kug
    Lee, Jongsuk R.
    2016 10TH INTERNATIONAL CONFERENCE ON INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING (IMIS), 2016, : 403 - 408
  • [27] Analysis of Feature Selection Techniques for Network Traffic Dataset
    Singh, Raman
    Kumar, Harish
    Singla, R. K.
    2013 INTERNATIONAL CONFERENCE ON MACHINE INTELLIGENCE AND RESEARCH ADVANCEMENT (ICMIRA 2013), 2013, : 42 - 46
  • [28] A feature analysis approach to network traffic in communication networks
    Zhao, Hong-Hao
    Dong, Hong-Yu
    Zhang, Xiao-Hui
    Ye, Qing
    Meng, Fan-Bo
    Sun, Xin-Yu
    Cao, Ying
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMMUNICATION AND ELECTRONIC INFORMATION ENGINEERING (CEIE 2016), 2016, 116 : 648 - 655
  • [29] Network traffic anomalies detection and identification with flow monitoring
    Nguyen, Huy Anh
    Nguyen, Tam Van
    Kim, Dong Il
    Choi, Deokjai
    2008 IFIP INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS NETWORKS, 2008, : 235 - +
  • [30] Intrusion Detection Using Flow-Based Analysis of Network Traffic
    David, Jisa
    Thomas, Ciza
    ADVANCES IN NETWORKS AND COMMUNICATIONS, PT II, 2011, 132 : 391 - 399