FlowGANAnomaly: Flow-Based Anomaly Network Intrusion Detection with Adversarial Learning

被引:0
|
作者
Zeyi LI [1 ]
Pan WANG [2 ]
Zixuan WANG [3 ]
机构
[1] School of Computer Science, Nanjing University of Posts and Telecommunications
[2] School of Modern Posts, Nanjing University of Posts and Telecommunications
[3] School of Internet of Things, Nanjing University of Posts and Telecommunications
关键词
D O I
暂无
中图分类号
TP393.08 []; TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 0839 ; 1402 ; 1405 ;
摘要
In recent years, low recall rates and high dependencies on data labelling have become the biggest obstacle to developing deep anomaly detection(DAD) techniques. Inspired by the success of generative adversarial networks(GANs) in detecting anomalies in computer vision and imaging, we propose an anomaly detection model called Flow GANAnomaly for detecting anomalous traffic in network intrusion detection systems(NIDS). Unlike traditional GAN-based approaches, which are composed of a flow encoder, a convolutional encoder-decoder-encoder, a flow decoder and a convolutional encoder, the architecture of this model consists of a generator(G) and a discriminator(D).Flow GANAnomaly maps the different types of traffic feature data from separate datasets to a uniform feature space,thus can capture the normality of network traffic data more accurately in an adversarial manner to mitigate the problem of the high dependence on data labeling. Moreover, instead of simply detecting the anomalies by the output of D, we proposed a new anomaly scoring method that integrates the deviation between the output of two Gs’ convolutional encoders with the output of D as weighted scores to improve the low recall rate of anomaly detection. We conducted several experiments comparing existing machine learning algorithms and existing deep learning methods(Auto Encoder and VAE) on four public datasets(NSL-KDD, CIC-IDS2017, CIC-DDo S2019, and UNSW-NB15). The evaluation results show that Flow GANAnomaly can significantly improve the performance of anomaly-based NIDS.
引用
收藏
页码:58 / 71
页数:14
相关论文
共 50 条
  • [1] FlowGANAnomaly: Flow-Based Anomaly Network Intrusion Detection with Adversarial Learning
    Li, Zeyi
    Wang, Pan
    Wang, Zixuan
    Zhan, De-chuan
    [J]. CHINESE JOURNAL OF ELECTRONICS, 2024, 33 (01) : 58 - 71
  • [2] Flow-Based Anomaly Intrusion Detection System Using Two Neural Network Stages
    Abuadlla, Yousef
    Kvascev, Goran
    Gajin, Slavko
    Jovanovic, Zoran
    [J]. COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2014, 11 (02) : 601 - 622
  • [3] Flow-based anomaly intrusion detection using machine learning model with software defined networking for OpenFlow network
    Satheesh, N.
    Rathnamma, M. V.
    Rajeshkumar, G.
    Sagar, P. Vidya
    Dadheech, Pankaj
    Dogiwal, S. R.
    Velayutham, Priya
    Sengan, Sudhakar
    [J]. MICROPROCESSORS AND MICROSYSTEMS, 2020, 79
  • [4] Intrusion Detection Using Flow-Based Analysis of Network Traffic
    David, Jisa
    Thomas, Ciza
    [J]. ADVANCES IN NETWORKS AND COMMUNICATIONS, PT II, 2011, 132 : 391 - 399
  • [5] Stream Learning and Anomaly-based Intrusion Detection in the Adversarial Settings
    Viegas, Eduardo
    Santin, Altair
    Abreu, Vilmar
    Oliveira, Luiz S.
    [J]. 2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 773 - 778
  • [6] Ensemble Learning Approach for Flow-based Intrusion Detection System
    Zwane, Skhumbuzo
    Tarwireyi, Paul
    Adigun, Matthew
    [J]. 2019 IEEE AFRICON, 2019,
  • [7] Analyzing Flow-based Anomaly Intrusion Detection using Replicator Neural Networks
    Cordero, Carlos Garcia
    Hauke, Sascha
    Muhlhauser, Max
    Fischert, Mathias
    [J]. 2016 14TH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2016,
  • [8] PGAN:A Generative Adversarial Network based Anomaly Detection Method for Network Intrusion Detection System
    Li, Zeyi
    Wang, Yun
    Wang, Pan
    Su, Haorui
    [J]. 2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 734 - 741
  • [9] Intelligent flow-based sampling for effective network anomaly detection
    Androulidakis, G.
    Papavassiliou, S.
    [J]. GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 1948 - 1953
  • [10] Flow-based statistical aggregation schemes for network anomaly detection
    Song, Sui
    Ling, Li
    Manikopoulo, C. N.
    [J]. PROCEEDINGS OF THE 2006 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, SENSING AND CONTROL, 2006, : 786 - 791