GEE: A Gradient-based Explainable Variational Autoencoder for Network Anomaly Detection

03/15/2019
by   Quoc Phong Nguyen, et al.
0

This paper looks into the problem of detecting network anomalies by analyzing NetFlow records. While many previous works have used statistical models and machine learning techniques in a supervised way, such solutions have the limitations that they require large amount of labeled data for training and are unlikely to detect zero-day attacks. Existing anomaly detection solutions also do not provide an easy way to explain or identify attacks in the anomalous traffic. To address these limitations, we develop and present GEE, a framework for detecting and explaining anomalies in network traffic. GEE comprises of two components: (i) Variational Autoencoder (VAE) - an unsupervised deep-learning technique for detecting anomalies, and (ii) a gradient-based fingerprinting technique for explaining anomalies. Evaluation of GEE on the recent UGR dataset demonstrates that our approach is effective in detecting different anomalies as well as identifying fingerprints that are good representations of these various attacks.

READ FULL TEXT
research
01/31/2022

StRegA: Unsupervised Anomaly Detection in Brain MRIs using a Compact Context-encoding Variational Autoencoder

Expert interpretation of anatomical images of the human brain is the cen...
research
05/14/2021

DoS and DDoS Mitigation Using Variational Autoencoders

DoS and DDoS attacks have been growing in size and number over the last ...
research
01/13/2019

A Machine-Synesthetic Approach To DDoS Network Attack Detection

In the authors' opinion, anomaly detection systems, or ADS, seem to be t...
research
12/15/2022

Anomaly Detection in Driving by Cluster Analysis Twice

Events deviating from normal traffic patterns in driving, anomalies, suc...
research
02/25/2022

Self-Supervised and Interpretable Anomaly Detection using Network Transformers

Monitoring traffic in computer networks is one of the core approaches fo...
research
04/27/2019

Exploring Information Centrality for Intrusion Detection in Large Networks

Modern networked systems are constantly under threat from systemic attac...
research
07/01/2019

Location Anomalies Detection for Connected and Autonomous Vehicles

Future Connected and Automated Vehicles (CAV), and more generally ITS, w...

Please sign up or login with your details

Forgot password? Click here to reset