Attention-based Encoder-Decoder Recurrent Neural Networks for HTTP Payload Anomaly Detection

被引:1
|
作者
Wu, Shang [1 ]
Wang, Yijie [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Sci & Technol Parallel & Distributed Proc Lab, Changsha, Peoples R China
基金
中国国家自然科学基金; 国家教育部科学基金资助;
关键词
HTTP Payload Anomaly Detection; Network Security; Deep learning; Encoder-Decoder Recurrent Neural Networks; Attention Mechanism; CLASSIFIER;
D O I
10.1109/ISPA-BDCloud-SocialCom-SustainCom52081.2021.00196
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Attack payloads are often short segments hidden in HTTP requests; thus they can be found by HTTP payload anomaly detection. Deep learning models learn data features during training without manual feature extraction, and better performance has received more attention. Recurrent Neural Network models process sequences directly, which are widely used in payload anomaly detection. However, due to the gradient vanishing problem, RNN has limits on processing the long sequences. Meanwhile, RNN uses its final hidden state for detection and pays more attention to the content of the end of the payload. Besides, deep learning generally lacks interpretability. The paper proposes an unsupervised deep learning model for HTTP payload Anomaly Detection, namely Attention-based Encoder-Decoder Recurrent Neural Networks Anomaly Detection model (AEDRAD). AEDRAD utilizes the encoder-decoder RNN and attention mechanism to detect anomalies by reconstructing the original sequences. AEDRAD filters the fields of HTTP protocol that cannot exist anomalies, focusing on the suspicious segments. Through the encoder-decoder network, the normal payload can be well-reconstructed while the anomaly payload fails. With the attention mechanism, AEDRAD generates practical features for further anomaly detection from a global perspective. Meanwhile, it marks abnormal fragments visually, which is conducive to a subsequent analysis by experts. The experimental results show that AEDRAD significantly outperforms three state-of-the-art unsupervised algorithms on two real datasets.
引用
收藏
页码:1452 / 1459
页数:8
相关论文
共 50 条
  • [1] Attention-based encoder-decoder networks for workflow recognition
    Min Zhang
    Haiyang Hu
    Zhongjin Li
    Jie Chen
    [J]. Multimedia Tools and Applications, 2021, 80 : 34973 - 34995
  • [2] Attention-based encoder-decoder networks for workflow recognition
    Zhang, Min
    Hu, Haiyang
    Li, Zhongjin
    Chen, Jie
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (28-29) : 34973 - 34995
  • [3] Video Summarization With Attention-Based Encoder-Decoder Networks
    Ji, Zhong
    Xiong, Kailin
    Pang, Yanwei
    Li, Xuelong
    [J]. IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2020, 30 (06) : 1709 - 1717
  • [4] Anomaly detection in smart grid based on encoder-decoder framework with recurrent neural network
    Zheng Fengming
    Li Shufang
    Guo Zhimin
    Wu Bo
    Tian Shiming
    Pan Mingming
    [J]. TheJournalofChinaUniversitiesofPostsandTelecommunications., 2017, 24 (06) - 73
  • [5] Anomaly detection in smart grid based on encoder-decoder framework with recurrent neural network
    Zheng Fengming
    Li Shufang
    Guo Zhimin
    Wu Bo
    Tian Shiming
    Pan Mingming
    [J]. The Journal of China Universities of Posts and Telecommunications, 2017, (06) : 67 - 73
  • [6] A Neural Attention-Based Encoder-Decoder Approach for English to Bangla Translation
    Al Shiam, Abdullah
    Redwan, Sadi Md.
    Kabir, Humaun
    Shin, Jungpil
    [J]. COMPUTER SCIENCE JOURNAL OF MOLDOVA, 2023, 31 (01) : 70 - 85
  • [7] Describing Multimedia Content Using Attention-Based Encoder-Decoder Networks
    Cho, Kyunghyun
    Courville, Aaron
    Bengio, Yoshua
    [J]. IEEE TRANSACTIONS ON MULTIMEDIA, 2015, 17 (11) : 1875 - 1886
  • [8] Dense Video Captioning with Hierarchical Attention-Based Encoder-Decoder Networks
    Yu, Mingjing
    Zheng, Huicheng
    Liu, Zehua
    [J]. 2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [9] Multiple attention-based encoder-decoder networks for gas meter character recognition
    Li, Weidong
    Wang, Shuai
    Ullah, Inam
    Zhang, Xuehai
    Duan, Jinlong
    [J]. SCIENTIFIC REPORTS, 2022, 12 (01)
  • [10] Pooling Attention-based Encoder-Decoder Network for semantic segmentation
    Xu, Haixia
    Huang, Yunjia
    Hancock, Edwin R.
    Wang, Shuailong
    Xuan, Qijun
    Zhou, Wei
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93