Attention-based Encoder-Decoder Recurrent Neural Networks for HTTP Payload Anomaly Detection

被引:1
|
作者
Wu, Shang [1 ]
Wang, Yijie [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Sci & Technol Parallel & Distributed Proc Lab, Changsha, Peoples R China
基金
中国国家自然科学基金; 国家教育部科学基金资助;
关键词
HTTP Payload Anomaly Detection; Network Security; Deep learning; Encoder-Decoder Recurrent Neural Networks; Attention Mechanism; CLASSIFIER;
D O I
10.1109/ISPA-BDCloud-SocialCom-SustainCom52081.2021.00196
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Attack payloads are often short segments hidden in HTTP requests; thus they can be found by HTTP payload anomaly detection. Deep learning models learn data features during training without manual feature extraction, and better performance has received more attention. Recurrent Neural Network models process sequences directly, which are widely used in payload anomaly detection. However, due to the gradient vanishing problem, RNN has limits on processing the long sequences. Meanwhile, RNN uses its final hidden state for detection and pays more attention to the content of the end of the payload. Besides, deep learning generally lacks interpretability. The paper proposes an unsupervised deep learning model for HTTP payload Anomaly Detection, namely Attention-based Encoder-Decoder Recurrent Neural Networks Anomaly Detection model (AEDRAD). AEDRAD utilizes the encoder-decoder RNN and attention mechanism to detect anomalies by reconstructing the original sequences. AEDRAD filters the fields of HTTP protocol that cannot exist anomalies, focusing on the suspicious segments. Through the encoder-decoder network, the normal payload can be well-reconstructed while the anomaly payload fails. With the attention mechanism, AEDRAD generates practical features for further anomaly detection from a global perspective. Meanwhile, it marks abnormal fragments visually, which is conducive to a subsequent analysis by experts. The experimental results show that AEDRAD significantly outperforms three state-of-the-art unsupervised algorithms on two real datasets.
引用
收藏
页码:1452 / 1459
页数:8
相关论文
共 50 条
  • [11] Attention-Based Encoder-Decoder End-to-End Neural Diarization With Embedding Enhancer
    Chen, Zhengyang
    Han, Bing
    Wang, Shuai
    Qian, Yanmin
    [J]. IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2024, 32 : 1636 - 1649
  • [12] Enhanced Attention-Based Encoder-Decoder Framework for Text Recognition
    Prabu, S.
    Sundar, K. Joseph Abraham
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2023, 35 (02): : 2071 - 2086
  • [13] ATTENTION-BASED ENCODER-DECODER NETWORK FOR SINGLE IMAGE DEHAZING
    Gao, Shunan
    Zhu, Jinghua
    Xi, Heran
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA & EXPO WORKSHOPS (ICMEW), 2021,
  • [14] Understanding attention-based encoder-decoder networks: a case study with chess scoresheet recognition
    Hayashi, Sergio Y.
    Hirata, Nina S. T.
    [J]. 2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 1586 - 1592
  • [15] An anomaly detection method based on double encoder-decoder generative adversarial networks
    Liu, Hui
    Tang, Tinglong
    Luo, Jake
    Zhao, Meng
    Zheng, Baole
    Wu, Yirong
    [J]. INDUSTRIAL ROBOT-THE INTERNATIONAL JOURNAL OF ROBOTICS RESEARCH AND APPLICATION, 2021, 48 (05): : 643 - 648
  • [16] Encoder-decoder based convolutional neural networks for image forgery detection
    El Biach, Fatima Zahra
    Iala, Imad
    Laanaya, Hicham
    Minaoui, Khalid
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (16) : 22611 - 22628
  • [17] Encoder-decoder based convolutional neural networks for image forgery detection
    Fatima Zahra El Biach
    Imad Iala
    Hicham Laanaya
    Khalid Minaoui
    [J]. Multimedia Tools and Applications, 2022, 81 : 22611 - 22628
  • [18] Arabic Machine Transliteration using an Attention-based Encoder-decoder Model
    Ameur, Mohamed Seghir Hadj
    Meziane, Farid
    Guessoum, Ahmed
    [J]. ARABIC COMPUTATIONAL LINGUISTICS (ACLING 2017), 2017, 117 : 287 - 297
  • [19] Attention-Based Encoder-Decoder Network for Prediction of Electromagnetic Scattering Fields
    Zhang, Ying
    He, Mang
    [J]. 2022 IEEE 10TH ASIA-PACIFIC CONFERENCE ON ANTENNAS AND PROPAGATION, APCAP, 2022,
  • [20] AUTOMATIC SINGING TRANSCRIPTION BASED ON ENCODER-DECODER RECURRENT NEURAL NETWORKS WITH A WEAKLY-SUPERVISED ATTENTION MECHANISM
    Nishikimi, Ryo
    Nakamura, Eita
    Fukayama, Satoru
    Goto, Masataka
    Yoshii, Kazuyoshi
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 161 - 165