Cross-Layer Profiling of Encrypted Network Data for Anomaly Detection

被引:5
|
作者
Meghdouri, Fares [1 ]
Vazquez, Felix Iglesias [1 ]
Zseby, Tanja [1 ]
机构
[1] TU Wien, Vienna, Austria
关键词
Network Data Analysis; Encrypted Communications; Anomaly Detection; Machine Learning;
D O I
10.1109/DSAA49011.2020.00061
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In January 2017 encrypted Internet traffic surpassed non-encrypted traffic. Although encryption increases security, it also masks intrusions and attacks by blocking the access to packet contents and traffic features, therefore making data analysis unfeasible. In spite of the strong effect of encryption, its impact has been scarcely investigated in the field. In this paper we study how encryption affects flow feature spaces and machine learning-based attack detection. We propose a new cross-layer feature vector that simultaneously represents traffic at three different levels: application, conversation, and endpoint behavior. We analyze its behavior under TLS and IPSec encryption and evaluate the efficacy with recent network traffic datasets and by using Random Forests classifiers. The cross-layer multi-key approach shows excellent attack detection in spite of TLS encryption. When IPsec is applied, the reduced variant obtains satisfactory detection for botnets, yet considerable performance drops for other types of attacks. The high complexity of network traffic is unfeasible for monolithic data analysis solutions, therefore requiring cross-layer analysis for which the multi-key vector becomes a powerful profiling core.
引用
收藏
页码:469 / 478
页数:10
相关论文
共 50 条
  • [21] A Cross-Layer, Anomaly-Based IDS for WSN and MANET
    Amouri, Amar
    Morgera, Salvatore D.
    Bencherif, Mohamed A.
    Manthena, Raju
    SENSORS, 2018, 18 (02):
  • [22] ANDROID MALWARE DETECTION BASED ON HETEROGENEOUS INFORMATION NETWORK WITH CROSS-LAYER FEATURES
    Ren Xixuan
    Zhao Lirui
    Wang Kai
    Xue Zhixing
    Hou Anran
    Shao Qiao
    2022 19TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2022,
  • [23] A Regularized Cross-Layer Ladder Network for Intrusion Detection in Industrial Internet of Things
    Long, Jing
    Liang, Wei
    Li, Kuan-Ching
    Wei, Yehua
    Marino, Mario Donato
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (02) : 1747 - 1755
  • [24] Android Malware Detection Based on Heterogeneous Information Network with Cross-Layer Features
    Xixuan, Ren
    Lirui, Zhao
    Kai, Wang
    Zhixing, Xue
    Anran, Hou
    Qiao, Shao
    2022 19th International Computer Conference on Wavelet Active Media Technology and Information Processing, ICCWAMTIP 2022, 2022,
  • [25] Construction and Analysis of Cross-layer Aggregation Neural Network for AMI Intrusion Detection
    Wang, Ning
    Liu, Zhihui
    Yao, Ruizhe
    Zhang, Li
    2022 4TH ASIA ENERGY AND ELECTRICAL ENGINEERING SYMPOSIUM (AEEES 2022), 2022, : 148 - 153
  • [26] Cross-Layer Attention Network for Small Object Detection in Remote Sensing Imagery
    Li, Yangyang
    Huang, Qin
    Pei, Xuan
    Chen, Yanqiao
    Jiao, Licheng
    Shang, Ronghua
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2021, 14 : 2148 - 2161
  • [27] Cross-layer Communication Power Allocation for Distributed Detection in Wireless Sensor Network
    Liu, Xiangyang
    Bai, Wenbin
    Cheng, Xiaoying
    Pan, Jin
    2011 IET 4TH INTERNATIONAL CONFERENCE ON WIRELESS, MOBILE & MULTIMEDIA NETWORKS (ICWMMN 2011), 2011, : 85 - 89
  • [28] Ignoring Encrypted Protocols: Cross-layer Prediction of Video Streaming QoE Metrics
    Junxin Chen
    Weimin Mai
    Xiaoqin Lian
    Mingyu Yang
    Qi Sun
    Chao Gao
    Cong Zhang
    Xiang Chen
    Mobile Networks and Applications, 2022, 27 : 2459 - 2468
  • [29] Ignoring Encrypted Protocols: Cross-layer Prediction of Video Streaming QoE Metrics
    Chen, Junxin
    Mai, Weimin
    Lian, Xiaoqin
    Yang, Mingyu
    Sun, Qi
    Gao, Chao
    Zhang, Cong
    Chen, Xiang
    MOBILE NETWORKS & APPLICATIONS, 2022, 27 (06): : 2459 - 2468
  • [30] Randomized algorithms for cross-layer network control
    Sharma, Gaurav
    Shroff, Ness B.
    Mazumdar, Ravi R.
    MILCOM 2006, VOLS 1-7, 2006, : 3643 - +