Novelty Detection in Network Traffic: Using Survival Analysis for Feature Identification

被引:2
|
作者
Bradley, Taylor [1 ]
Alhajjar, Elie [2 ]
Bastian, Nathaniel D. [2 ]
机构
[1] Johns Hopkins Univ, Whiting Sch Engn, Baltimore, MD 21218 USA
[2] US Mil Acad, Army Cyber Inst, West Point, NY USA
关键词
Novelty detection; network traffic; cyber attacks; machine learning; survival analysis;
D O I
10.1109/ICAA58325.2023.00010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection Systems (NIDS) are an important component of many organizations' cyber defense, resiliency and assurance strategies. However, one downside of these systems is their reliance on known attack signatures for detection of malicious network events. When it comes to unknown attack types and zero-day exploits, even modern machine learning based NIDS often fall short. In this paper, we introduce an unconventional approach to identifying network traffic features that influence novelty detection based on survival analysis techniques. Specifically, we combine several Cox proportional hazards models and implement Kaplan-Meier estimates to predict the probability that a classifier identifies novelty after the injection of an unknown network attack at any given time. The proposed model is successful at pinpointing PSH Flag Count, ACK Flag Count, URG Flag Count, and Down/Up Ratio as the main features to impact novelty detection via Random Forest, Bayesian Ridge, and Linear Support Vector Regression classifiers.
引用
收藏
页码:11 / 18
页数:8
相关论文
共 50 条
  • [31] Early web application attack detection using network traffic analysis
    Rajic, Branislav
    Stanisavljevic, Zarko
    Vuletic, Pavle
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (01) : 77 - 91
  • [32] Early web application attack detection using network traffic analysis
    Branislav Rajić
    Žarko Stanisavljević
    Pavle Vuletić
    International Journal of Information Security, 2023, 22 : 77 - 91
  • [33] Multi-Feature Fusion Identification of Important Nodes in Traffic Network
    Xiao, Yuxin
    Hu, Jianming
    Zhang, Zuo
    Zhang, Yi
    INTERNATIONAL CONFERENCE ON TRANSPORTATION AND DEVELOPMENT 2020 - TRAFFIC AND BIKE/PEDESTRIAN OPERATIONS, 2020, : 169 - 180
  • [34] An Improved Jump Spider Optimization for Network Traffic Identification Feature Selection
    Xu, Hui
    Hu, Yalin
    Cao, Weidong
    Han, Longjie
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 76 (03): : 3239 - 3255
  • [35] An optimal feature based network intrusion detection system using bagging ensemble method for real-time traffic analysis
    Chowdhury, Ratul
    Sen, Shibaprasad
    Roy, Arindam
    Saha, Banani
    MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (28) : 41225 - 41247
  • [36] An optimal feature based network intrusion detection system using bagging ensemble method for real-time traffic analysis
    Ratul Chowdhury
    Shibaprasad Sen
    Arindam Roy
    Banani Saha
    Multimedia Tools and Applications, 2022, 81 : 41225 - 41247
  • [37] Hierarchical Novelty Detection for Traffic Sign Recognition
    Ruiz, Idoia
    Serrat, Joan
    SENSORS, 2022, 22 (12)
  • [38] Traffic identification using artificial neural network
    Ali, AA
    Tervo, R
    CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING 2001, VOLS I AND II, CONFERENCE PROCEEDINGS, 2001, : 667 - 672
  • [39] Feature extraction for traffic incident detection using wavelet transform and linear discriminant analysis
    Samant, A
    Adeli, H
    COMPUTER-AIDED CIVIL AND INFRASTRUCTURE ENGINEERING, 2000, 15 (04) : 241 - 250
  • [40] Feature Extraction of Network Traffic in Ethereum Blockchain Network Layer for Eclipse Attack Detection
    Bhumichai, Dhanasak
    Benton, Ryan
    SOUTHEASTCON 2023, 2023, : 869 - 876