Novelty Detection in Network Traffic: Using Survival Analysis for Feature Identification

01/16/2023
by   Taylor Bradley, et al.
0

Intrusion Detection Systems are an important component of many organizations' cyber defense and resiliency strategies. However, one downside of these systems is their reliance on known attack signatures for detection of malicious network events. When it comes to unknown attack types and zero-day exploits, modern Intrusion Detection Systems often fall short. In this paper, we introduce an unconventional approach to identifying network traffic features that influence novelty detection based on survival analysis techniques. Specifically, we combine several Cox proportional hazards models and implement Kaplan-Meier estimates to predict the probability that a classifier identifies novelty after the injection of an unknown network attack at any given time. The proposed model is successful at pinpointing PSH Flag Count, ACK Flag Count, URG Flag Count, and Down/Up Ratio as the main features to impact novelty detection via Random Forest, Bayesian Ridge, and Linear Support Vector Regression classifiers.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/09/2012

Classification of artificial intelligence ids for smurf attack

Many methods have been developed to secure the network infrastructure an...
research
08/20/2021

An Adaptable Deep Learning-Based Intrusion Detection System to Zero-Day Attacks

The intrusion detection system (IDS) is an essential element of security...
research
07/21/2023

Identifying Relevant Features of CSE-CIC-IDS2018 Dataset for the Development of an Intrusion Detection System

Intrusion detection systems (IDSs) are essential elements of IT systems....
research
03/13/2021

Image Classifiers for Network Intrusions

This research recasts the network attack dataset from UNSW-NB15 as an in...
research
02/28/2022

Prepare for Trouble and Make it Double. Supervised and Unsupervised Stacking for AnomalyBased Intrusion Detection

In the last decades, researchers, practitioners and companies struggled ...
research
07/02/2023

3D-IDS: Doubly Disentangled Dynamic Intrusion Detection

Network-based intrusion detection system (NIDS) monitors network traffic...
research
10/16/2021

An Effective Attack Scenario Construction Model based on Attack Steps and Stages Identification

A Network Intrusion Detection System (NIDS) is a network security techno...

Please sign up or login with your details

Forgot password? Click here to reset