NetSentry: A Deep Learning Approach to Detecting Incipient Large-scale Network Attacks

02/20/2022
by   Haoyu Liu, et al.
0

Machine Learning (ML) techniques are increasingly adopted to tackle ever-evolving high-profile network attacks, including DDoS, botnet, and ransomware, due to their unique ability to extract complex patterns hidden in data streams. These approaches are however routinely validated with data collected in the same environment, and their performance degrades when deployed in different network topologies and/or applied on previously unseen traffic, as we uncover. This suggests malicious/benign behaviors are largely learned superficially and ML-based Network Intrusion Detection System (NIDS) need revisiting, to be effective in practice. In this paper we dive into the mechanics of large-scale network attacks, with a view to understanding how to use ML for Network Intrusion Detection (NID) in a principled way. We reveal that, although cyberattacks vary significantly in terms of payloads, vectors and targets, their early stages, which are critical to successful attack outcomes, share many similarities and exhibit important temporal correlations. Therefore, we treat NID as a time-sensitive task and propose NetSentry, perhaps the first of its kind NIDS that builds on Bidirectional Asymmetric LSTM (Bi-ALSTM), an original ensemble of sequential neural models, to detect network threats before they spread. We cross-evaluate NetSentry using two practical datasets, training on one and testing on the other, and demonstrate F1 score gains above 33 rates of detecting attacks such as XSS and web bruteforce. Further, we put forward a novel data augmentation technique that boosts the generalization abilities of a broad range of supervised deep learning algorithms, leading to average F1 score gains above 35

READ FULL TEXT

page 1

page 10

page 11

research
06/15/2023

Host-Based Network Intrusion Detection via Feature Flattening and Two-stage Collaborative Classifier

Network Intrusion Detection Systems (NIDS) have been extensively investi...
research
06/25/2022

Robustness Evaluation of Deep Unsupervised Learning Algorithms for Intrusion Detection Systems

Recently, advances in deep learning have been observed in various fields...
research
08/02/2023

IIDS: Design of Intelligent Intrusion Detection System for Internet-of-Things Applications

With rapid technological growth, security attacks are drastically increa...
research
06/15/2021

On the Evaluation of Sequential Machine Learning for Network Intrusion Detection

Recent advances in deep learning renewed the research interests in machi...
research
05/19/2021

Hunter in the Dark: Discover Anomalous Network Activity Using Deep Ensemble Network

Machine learning (ML)-based network intrusion detection system (NIDS) pl...
research
11/08/2022

A Hypergraph-Based Machine Learning Ensemble Network Intrusion Detection System

Network intrusion detection systems (NIDS) to detect malicious attacks c...
research
03/21/2022

Ovid: A Machine Learning Approach for Automated Vandalism Detection in OpenStreetMap

OpenStreetMap is a unique source of openly available worldwide map data,...

Please sign up or login with your details

Forgot password? Click here to reset