ARCADE: Adversarially Regularized Convolutional Autoencoder for Network Anomaly Detection

05/03/2022
by   Willian T. Lunardi, et al.
11

As the number of heterogenous IP-connected devices and traffic volume increase, so does the potential for security breaches. The undetected exploitation of these breaches can bring severe cybersecurity and privacy risks. In this paper, we present a practical unsupervised anomaly-based deep learning detection system called ARCADE (Adversarially Regularized Convolutional Autoencoder for unsupervised network anomaly DEtection). ARCADE exploits the property of 1D Convolutional Neural Networks (CNNs) and Generative Adversarial Networks (GAN) to automatically build a profile of the normal traffic based on a subset of raw bytes of a few initial packets of network flows so that potential network anomalies and intrusions can be effectively detected before they could cause any more damage to the network. A convolutional Autoencoder (AE) is proposed that suits online detection in resource-constrained environments, and can be easily improved for environments with higher computational capabilities. An adversarial training strategy is proposed to regularize and decrease the AE's capabilities to reconstruct network flows that are out of the normal distribution, and thereby improve its anomaly detection capabilities. The proposed approach is more effective than existing state-of-the-art deep learning approaches for network anomaly detection and significantly reduces detection time. The evaluation results show that the proposed approach is suitable for anomaly detection on resource-constrained hardware platforms such as Raspberry Pi.

READ FULL TEXT

page 1

page 4

page 10

research
08/01/2018

Anomaly Detection via Minimum Likelihood Generative Adversarial Networks

Anomaly detection aims to detect abnormal events by a model of normality...
research
02/12/2020

LUCID: A Practical, Lightweight Deep Learning Solution for DDoS Attack Detection

Distributed Denial of Service (DDoS) attacks are one of the most harmful...
research
11/12/2020

Image Anomaly Detection by Aggregating Deep Pyramidal Representations

Anomaly detection consists in identifying, within a dataset, those sampl...
research
02/05/2020

Anomaly Detection by Latent Regularized Dual Adversarial Networks

Anomaly detection is a fundamental problem in computer vision area with ...
research
12/16/2022

Resource-Interaction Graph: Efficient Graph Representation for Anomaly Detection

Security research has concentrated on converting operating system audit ...
research
06/17/2019

A baseline for unsupervised advanced persistent threat detection in system-level provenance

Advanced persistent threats (APT) are stealthy, sophisticated, and unpre...
research
01/28/2019

Heartbeat Anomaly Detection using Adversarial Oversampling

Cardiovascular diseases are one of the most common causes of death in th...

Please sign up or login with your details

Forgot password? Click here to reset