Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection

02/25/2018
by   Yisroel Mirsky, et al.
0

Neural networks have become an increasingly popular solution for network intrusion detection systems (NIDS). Their capability of learning complex patterns and behaviors make them a suitable solution for differentiating between normal traffic and network attacks. However, a drawback of neural networks is the amount of resources needed to train them. Many network gateways and routers devices, which could potentially host an NIDS, simply do not have the memory or processing power to train and sometimes even execute such models. More importantly, the existing neural network solutions are trained in a supervised manner. Meaning that an expert must label the network traffic and update the model manually from time to time. In this paper, we present Kitsune: a plug and play NIDS which can learn to detect attacks on the local network, without supervision, and in an efficient online manner. Kitsune's core algorithm (KitNET) uses an ensemble of neural networks called autoencoders to collectively differentiate between normal and abnormal traffic patterns. KitNET is supported by a feature extraction framework which efficiently tracks the patterns of every network channel. Our evaluations show that Kitsune can detect various attacks with a performance comparable to offline anomaly detectors, even on a Raspberry PI. This demonstrates that Kitsune can be a practical and economic NIDS.

READ FULL TEXT

page 6

page 10

page 11

page 12

page 13

research
08/09/2020

Enhancing Robustness Against Adversarial Examples in Network Intrusion Detection Systems

The increase of cyber attacks in both the numbers and varieties in recen...
research
07/21/2020

SSIDS: Semi-Supervised Intrusion Detection System by Extending the Logical Analysis of Data

Prevention of cyber attacks on the critical network resources has become...
research
12/13/2020

Application of deep learning to enhance the accuracy of intrusion detection in modern computer networks

Application of deep learning to enhance the accuracy of intrusion detect...
research
03/07/2018

Vesper: Using Echo-Analysis to Detect Man-in-the-Middle Attacks in LANs

The Man-in-the-Middle (MitM) attack is a cyber-attack in which an attack...
research
01/16/2014

Intrusion Detection using Continuous Time Bayesian Networks

Intrusion detection systems (IDSs) fall into two high-level categories: ...
research
08/03/2021

HTTP2vec: Embedding of HTTP Requests for Detection of Anomalous Traffic

Hypertext transfer protocol (HTTP) is one of the most widely used protoc...
research
04/28/2022

An Online Ensemble Learning Model for Detecting Attacks in Wireless Sensor Networks

In today's modern world, the usage of technology is unavoidable and the ...

Please sign up or login with your details

Forgot password? Click here to reset