Sequence Aggregation Rules for Anomaly Detection in Computer Network Traffic

05/09/2018
by   Benjamin J. Radford, et al.
0

We evaluate methods for applying unsupervised anomaly detection to cybersecurity applications on computer network traffic data, or flow. We borrow from the natural language processing literature and conceptualize flow as a sort of "language" spoken between machines. Five sequence aggregation rules are evaluated for their efficacy in flagging multiple attack types in a labeled flow dataset, CICIDS2017. For sequence modeling, we rely on long short-term memory (LSTM) recurrent neural networks (RNN). Additionally, a simple frequency-based model is described and its performance with respect to attack detection is compared to the LSTM models. We conclude that the frequency-based model tends to perform as well as or better than the LSTM models for the tasks at hand, with a few notable exceptions.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/28/2018

Network Traffic Anomaly Detection Using Recurrent Neural Networks

We show that a recurrent neural network is able to learn a model to repr...
research
07/17/2018

Comparison of RNN Encoder-Decoder Models for Anomaly Detection

In this paper, we compare different types of Recurrent Neural Network (R...
research
09/13/2019

LSTM-Based Anomaly Detection: Detection Rules from Extreme Value Theory

In this paper, we explore various statistical techniques for anomaly det...
research
01/01/2019

Augmentation Scheme for Dealing with Imbalanced Network Traffic Classification Using Deep Learning

One of the most important tasks in network management is identifying dif...
research
09/13/2021

Applications of Recurrent Neural Network for Biometric Authentication Anomaly Detection

Recurrent Neural Networks are powerful machine learning frameworks that ...
research
10/30/2018

DeepHTTP: Semantics-Structure Model with Attention for Anomalous HTTP Traffic Detection and Pattern Mining

In the Internet age, cyber-attacks occur frequently with complex types. ...
research
10/25/2017

Unsupervised and Semi-supervised Anomaly Detection with LSTM Neural Networks

We investigate anomaly detection in an unsupervised framework and introd...

Please sign up or login with your details

Forgot password? Click here to reset