Novelty Detection in Network Traffic: Using Survival Analysis for Feature Identification

被引:2
|
作者
Bradley, Taylor [1 ]
Alhajjar, Elie [2 ]
Bastian, Nathaniel D. [2 ]
机构
[1] Johns Hopkins Univ, Whiting Sch Engn, Baltimore, MD 21218 USA
[2] US Mil Acad, Army Cyber Inst, West Point, NY USA
关键词
Novelty detection; network traffic; cyber attacks; machine learning; survival analysis;
D O I
10.1109/ICAA58325.2023.00010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection Systems (NIDS) are an important component of many organizations' cyber defense, resiliency and assurance strategies. However, one downside of these systems is their reliance on known attack signatures for detection of malicious network events. When it comes to unknown attack types and zero-day exploits, even modern machine learning based NIDS often fall short. In this paper, we introduce an unconventional approach to identifying network traffic features that influence novelty detection based on survival analysis techniques. Specifically, we combine several Cox proportional hazards models and implement Kaplan-Meier estimates to predict the probability that a classifier identifies novelty after the injection of an unknown network attack at any given time. The proposed model is successful at pinpointing PSH Flag Count, ACK Flag Count, URG Flag Count, and Down/Up Ratio as the main features to impact novelty detection via Random Forest, Bayesian Ridge, and Linear Support Vector Regression classifiers.
引用
收藏
页码:11 / 18
页数:8
相关论文
共 50 条
  • [41] Traffic Sign Detection Based on Lightweight Multiscale Feature Fusion Network
    Lin, Shan
    Zhang, Zicheng
    Tao, Jie
    Zhang, Fan
    Fan, Xing
    Lu, Qingchang
    SUSTAINABILITY, 2022, 14 (21)
  • [42] FAMN: Feature Aggregation Multipath Network for Small Traffic Sign Detection
    Ou, Zhonghong
    Xiao, Fenrui
    Xiong, Baiqiao
    Shi, Shenda
    Song, Meina
    IEEE ACCESS, 2019, 7 : 178798 - 178810
  • [43] Network Traffic Feature Weight Map Based Approach for Intrusion Detection
    Zhang, Jianwu
    Zhang, Yu
    Fu, Xingbing
    An, Yanjun
    Yang, Yuhang
    Li, Fagen
    International Journal of Network Security, 2022, 24 (02) : 253 - 261
  • [44] Network Traffic Anomaly Detection Method Based on a Feature of Catastrophe Theory
    Yang Yue
    Hu Han-Ping
    Xiong Wei
    Chen Jiang-Hang
    CHINESE PHYSICS LETTERS, 2010, 27 (06)
  • [45] Malicious encrypted network traffic flow detection using enhanced optimal deep feature selection with DLSTM
    Hublikar, Shivaraj
    Shet, N. Shekar V.
    INTERNATIONAL JOURNAL OF MODELING SIMULATION AND SCIENTIFIC COMPUTING, 2024, 15 (01)
  • [46] Malicious Encrypted Network Traffic Flow Detection using Optimal Feature Extraction with Deep Neural Networks
    Hublikar, Shivaraj
    Budihal, Sunita
    Shet, N. S., V
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2022, 17 (05): : 175 - 183
  • [47] Feature extraction for novelty detection as applied to fault detection in machinery
    McBain, Jordan
    Timusk, Markus
    PATTERN RECOGNITION LETTERS, 2011, 32 (07) : 1054 - 1061
  • [48] Combining MIC Feature Selection and Feature-based MSPCA for Network Traffic Anomaly Detection
    Chen, Zhaomin
    Yeo, Chai Kiat
    Francis, Bu Sung Lee
    Lau, Chiew Tong
    2016 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION PROCESSING, DATA MINING, AND WIRELESS COMMUNICATIONS (DIPDMWC), 2016, : 176 - 181
  • [49] USING R FOR ANOMALY DETECTION IN NETWORK TRAFFIC
    Hock, Denis
    Kappes, Martin
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON INTERNET TECHNOLOGIES AND APPLICATIONS (ITA 13), 2013, : 98 - 105
  • [50] ECG Anomalies Identification Using a Time Series Novelty Detection Technique
    Lemos, A. P.
    Tierra-Criollo, C. J.
    Caminhas, W. M.
    IV LATIN AMERICAN CONGRESS ON BIOMEDICAL ENGINEERING 2007, BIOENGINEERING SOLUTIONS FOR LATIN AMERICA HEALTH, VOLS 1 AND 2, 2008, 18 (1,2): : 65 - 68