A Combination of Temporal Sequence Learning and Data Description for Anomaly-based NIDS

06/07/2019
by   Nguyen Thanh Van, et al.
0

Through continuous observation and modeling of normal behavior in networks, Anomaly-based Network Intrusion Detection System (A-NIDS) offers a way to find possible threats via deviation from the normal model. The analysis of network traffic based on the time series model has the advantage of exploiting the relationship between packages within network traffic and observing trends of behaviors over a period of time. It will generate new sequences with good features that support anomaly detection in network traffic and provide the ability to detect new attacks. Besides, an anomaly detection technique, which focuses on the normal data and aims to build a description of it, will be an effective technique for anomaly detection in imbalanced data. In this paper, we propose a combination model of Long Short Term Memory (LSTM) architecture for processing time series and a data description Support Vector Data Description (SVDD) for anomaly detection in A-NIDS to obtain the advantages of them. This model helps parameters in LSTM and SVDD are jointly trained with the joint optimization method. Our experimental results with KDD99 dataset show that the proposed combined model obtains high performance in intrusion detection, especially DoS and Probe attacks with 98.0

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/31/2018

One-class Collective Anomaly Detection based on Long Short-Term Memory Recurrent Neural Networks

Intrusion detection for computer network systems has been becoming one o...
research
11/26/2019

Network Intrusion Detection based on LSTM and Feature Embedding

Growing number of network devices and services have led to increasing de...
research
11/01/2019

THAAD: Efficient Matching Queries under Temporal Abstraction for Anomaly Detection

In this paper we present a novel algorithm and efficient data structure ...
research
05/25/2020

Unsupervised Online Anomaly Detection On Irregularly Sampled Or Missing Valued Time-Series Data Using LSTM Networks

We study anomaly detection and introduce an algorithm that processes var...
research
10/25/2017

Unsupervised and Semi-supervised Anomaly Detection with LSTM Neural Networks

We investigate anomaly detection in an unsupervised framework and introd...
research
04/07/2022

Autoencoder-based Unsupervised Intrusion Detection using Multi-Scale Convolutional Recurrent Networks

The massive growth of network traffic data leads to a large volume of da...
research
11/29/2018

A Machine-Learning Phase Classification Scheme for Anomaly Detection in Signals with Periodic Characteristics

In this paper we propose a novel machine-learning method for anomaly det...

Please sign up or login with your details

Forgot password? Click here to reset