Autoencoder-based Unsupervised Intrusion Detection using Multi-Scale Convolutional Recurrent Networks

04/07/2022
by   Amardeep Singh, et al.
0

The massive growth of network traffic data leads to a large volume of datasets. Labeling these datasets for identifying intrusion attacks is very laborious and error-prone. Furthermore, network traffic data have complex time-varying non-linear relationships. The existing state-of-the-art intrusion detection solutions use a combination of various supervised approaches along with fused features subsets based on correlations in traffic data. These solutions often require high computational cost, manual support in fine-tuning intrusion detection models, and labeling of data that limit real-time processing of network traffic. Unsupervised solutions do reduce computational complexities and manual support for labeling data but current unsupervised solutions do not consider spatio-temporal correlations in traffic data. To address this, we propose a unified Autoencoder based on combining multi-scale convolutional neural network and long short-term memory (MSCNN-LSTM-AE) for anomaly detection in network traffic. The model first employs Multiscale Convolutional Neural Network Autoencoder (MSCNN-AE) to analyze the spatial features of the dataset, and then latent space features learned from MSCNN-AE employs Long Short-Term Memory (LSTM) based Autoencoder Network to process the temporal features. Our model further employs two Isolation Forest algorithms as error correction mechanisms to detect false positives and false negatives to improve detection accuracy. Riemannian manifold that is naturally embedded with distance metrices that facilitates descriminative patterns for detecting malicious network traffic. We evaluated our model NSL-KDD, UNSW-NB15, and CICDDoS2019 dataset and showed our proposed method significantly outperforms the conventional unsupervised methods and other existing studies on the dataset.

READ FULL TEXT

page 8

page 9

research
10/31/2021

Intrusion Detection using Spatial-Temporal features based on Riemannian Manifold

Network traffic data is a combination of different data bytes packets un...
research
06/07/2019

A Combination of Temporal Sequence Learning and Data Description for Anomaly-based NIDS

Through continuous observation and modeling of normal behavior in networ...
research
11/26/2019

Network Intrusion Detection based on LSTM and Feature Embedding

Growing number of network devices and services have led to increasing de...
research
08/13/2020

Detecting Abnormal Traffic in Large-Scale Networks

With the rapid technological advancements, organizations need to rapidly...
research
08/13/2022

CANdito: Improving Payload-based Detection of Attacks on Controller Area Networks

Over the years, the increasingly complex and interconnected vehicles rai...
research
08/20/2021

Suspicious ARP Activity Detection and Clustering Based on Autoencoder Neural Networks

The rapidly increasing number of smart devices on the Internet necessita...
research
12/03/2021

Two-stage Deep Stacked Autoencoder with Shallow Learning for Network Intrusion Detection System

Sparse events, such as malign attacks in real-time network traffic, have...

Please sign up or login with your details

Forgot password? Click here to reset