Realtime Robust Malicious Traffic Detection via Frequency Domain Analysis

06/28/2021
by   Chuanpu Fu, et al.
0

Machine learning (ML) based malicious traffic detection is an emerging security paradigm, particularly for zero-day attack detection, which is complementary to existing rule based detection. However, the existing ML based detection has low detection accuracy and low throughput incurred by inefficient traffic features extraction. Thus, they cannot detect attacks in realtime especially in high throughput networks. Particularly, these detection systems similar to the existing rule based detection can be easily evaded by sophisticated attacks. To this end, we propose Whisper, a realtime ML based malicious traffic detection system that achieves both high accuracy and high throughput by utilizing frequency domain features. It utilizes sequential features represented by the frequency domain features to achieve bounded information loss, which ensures high detection accuracy, and meanwhile constrains the scale of features to achieve high detection throughput. Particularly, attackers cannot easily interfere with the frequency domain features and thus Whisper is robust against various evasion attacks. Our experiments with 42 types of attacks demonstrate that, compared with the state-of-theart systems, Whisper can accurately detect various sophisticated and stealthy attacks, achieving at most 18.36 orders of magnitude throughput. Even under various evasion attacks, Whisper is still able to maintain around 90

READ FULL TEXT

page 5

page 16

research
01/31/2023

Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph Analysis

In this paper, we propose HyperVision, a realtime unsupervised machine l...
research
02/12/2023

Machine Learning Assisted Bad Data Detection for High-throughput Substation Communication

Electrical substations are becoming more prone to cyber-attacks due to i...
research
09/05/2021

A Transformer-based Model to Detect Phishing URLs

Phishing attacks are among emerging security issues that recently draws ...
research
02/22/2019

A Graph-Based Machine Learning Approach for Bot Detection

Bot detection using machine learning (ML), with network flow-level featu...
research
04/09/2019

Malicious Overtones: hunting data theft in the frequency domain with one-class learning

A method for detecting electronic data theft from computer networks is d...
research
06/03/2021

In-Network Freshness Control: Trading Throughput for Freshness

In addition to traditional concerns such as throughput and latency, fres...
research
09/04/2019

HinDom: A Robust Malicious Domain Detection System based on Heterogeneous Information Network with Transductive Classification

Domain name system (DNS) is a crucial part of the Internet, yet has been...

Please sign up or login with your details

Forgot password? Click here to reset