SFE-GACN: A Novel Unknown Attack Detection Method Using Intra Categories Generation in Embedding Space

04/12/2020
by   Ao Liu, et al.
0

In the encrypted network traffic intrusion detection, deep learning based schemes have attracted lots of attention. However, in real-world scenarios, data is often insufficient (few-shot), which leads to various deviations between the models prediction and the ground truth. Consequently, downstream tasks such as unknown attack detection based on few-shot will be limited by insufficient data. In this paper, we propose a novel unknown attack detection method based on Intra Categories Generation in Embedding Space, namely SFE-GACN, which might be the solution of few-shot problem. Concretely, we first proposed Session Feature Embedding (SFE) to summarize the context of sessions (session is the basic granularity of network traffic), bring the insufficient data to the pre-trained embedding space. In this way, we achieve the goal of preliminary information extension in the few-shot case. Second, we further propose the Generative Adversarial Cooperative Network (GACN), which improves the conventional Generative Adversarial Network by supervising the generated sample to avoid falling into similar categories, and thus enables samples to generate intra categories. Our proposed SFE-GACN can accurately generate session samples in the case of few-shot, and ensure the difference between categories during data augmentation. The detection results show that, compared to the state-of-the-art method, the average TPR is 8.38 average FPR is 12.77 capabilities of GACN on the graphics dataset, the result shows our proposed GACN can be popularized for generating easy-confused multi-categories graphics.

READ FULL TEXT
research
12/04/2021

Implicit Data Augmentation Using Feature Interpolation for Diversified Low-Shot Image Generation

Training of generative models especially Generative Adversarial Networks...
research
10/06/2021

PWG-IDS: An Intrusion Detection Model for Solving Class Imbalance in IIoT Networks Using Generative Adversarial Networks

With the continuous development of industrial IoT (IIoT) technology, net...
research
11/05/2022

Prototypical quadruplet for few-shot class incremental learning

Many modern computer vision algorithms suffer from two major bottlenecks...
research
02/26/2023

APT Encrypted Traffic Detection Method based on Two-Parties and Multi-Session for IoT

APT traffic detection is an important task in network security domain, w...
research
08/11/2023

Diverse Data Augmentation with Diffusions for Effective Test-time Prompt Tuning

Benefiting from prompt tuning, recent years have witnessed the promising...
research
04/06/2019

Unsupervised Embedding Learning via Invariant and Spreading Instance Feature

This paper studies the unsupervised embedding learning problem, which re...
research
10/13/2020

Session-layer Attack Traffic Classification by Program Synthesis

Writing classification rules to identify malicious network traffic is a ...

Please sign up or login with your details

Forgot password? Click here to reset