Data Exfiltration Detection on Network Metadata with Autoencoders

被引:2
|
作者
Willems, Daan [1 ]
Kohls, Katharina [2 ]
van der Kamp, Bob [1 ]
Vranken, Harald [2 ,3 ]
机构
[1] Minist Justice & Secur, Natl Cyber Secur Ctr NCSC, NL-2511 DP The Hague, Netherlands
[2] Radboud Univ Nijmegen, Inst Comp & Informat Sci, Fac Sci, NL-6525 AJ Nijmegen, Netherlands
[3] Open Univ Netherlands, Fac Sci, Dept Comp Sci, NL-6419 AT Heerlen, Netherlands
关键词
network intrusion detection; data exfiltration; autoencoder; anomaly detection; ANOMALY DETECTION;
D O I
10.3390/electronics12122584
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We designed a Network Exfiltration Detection System (NEDS) to detect data exfiltration as occurring in ransomware attacks. The NEDS operates on aggregated metadata, which is more privacy-friendly and allows analysis of large volumes of high-speed network traffic. The NEDS aggregates metadata from multiple, sequential sessions between pairs of hosts in a network, which captures exfiltration by both stateful and stateless protocols. The aggregated metadata include averages per session of both packet count, request entropy, duration, and payload size, as well as the average time between sequential sessions and the amount of aggregated sessions. The NEDS applies a number of autoencoder models with unsupervised learning to detect anomalies, where each autoencoder model targets different protocols. We trained the autoencoder models with real-life data collected at network sensors in the National Detection Network as operated by the National Cyber Security Centre in the Netherlands, and configured the detection threshold by varying the false positive rate. We evaluated the detection performance by injecting exfiltration over different channels, including DNS tunnels and uploads to FTP servers, web servers, and cloud storage. Our experimental results show that aggregation significantly increases detection performance of exfiltration that happens over longer time, most notably, DNS tunnels. Our NEDS can be applied to detect exfiltration either in near-real-time data analysis with limited false positive rates, or in captured data to aid in post-incident analysis.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] Landmine Detection Using Autoencoders on Multipolarization GPR Volumetric Data
    Bestagini, Paolo
    Lombardi, Federico
    Lualdi, Maurizio
    Picetti, Francesco
    Tubaro, Stefano
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2021, 59 (01): : 182 - 195
  • [42] Ensemble of Autoencoders for Anomaly Detection in Biomedical Data: A Narrative Review
    Nawaz, Ali
    Khan, Shehroz S.
    Ahmad, Amir
    IEEE ACCESS, 2024, 12 : 17273 - 17289
  • [43] A DNS Tunneling Detection Method Based on Deep Learning Models to Prevent Data Exfiltration
    Zhang, Jiacheng
    Yang, Li
    Yu, Shui
    Ma, Jianfeng
    NETWORK AND SYSTEM SECURITY, NSS 2019, 2019, 11928 : 520 - 535
  • [44] Fishing Activity Detection from AIS Data Using Autoencoders
    Jiang, Xiang
    Silver, Daniel L.
    Hu, Baifan
    de Souza, Erico N.
    Matwin, Stan
    ADVANCES IN ARTIFICIAL INTELLIGENCE, AI 2016, 2016, 9673 : 33 - 39
  • [45] APPLICATION OF AUTOENCODERS ON MULTIVARIATE ANOMALY DETECTION IN BUILDING AUTOMATION SYSTEMS WITH VARIABLE SELECTION BASED ON SEMANTIC METADATA OF THE FACILITY
    Šipetić, Miloš
    Schöny, Michael
    Catal, Jerik
    37th International Conference on Efficiency, Cost, Optimization, Simulation and Environmental Impact of Energy Systems, ECOS 2024, 2024, 1 : 699 - 710
  • [46] Data Exfiltration Techniques and Data Loss Prevention System
    AlKilani, Hamzeh
    Nasereddin, Mohammed
    Hadi, Ali
    Tedmori, Sara
    2019 INTERNATIONAL ARAB CONFERENCE ON INFORMATION TECHNOLOGY (ACIT), 2019, : 124 - 127
  • [47] AEGR: a simple approach to gradient reversal in autoencoders for network anomaly detection
    Babaei, Kasra
    Chen, Zhi Yuan
    Maul, Tomas
    SOFT COMPUTING, 2021, 25 (24) : 15269 - 15280
  • [48] Anomaly based Resilient Network Intrusion Detection using Inferential Autoencoders
    Hannan, Abdul
    Gruhl, Christian
    Sick, Bernhard
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 1 - 7
  • [49] Unsupervised learning approach for network intrusion detection system using autoencoders
    Hyunseung Choi
    Mintae Kim
    Gyubok Lee
    Wooju Kim
    The Journal of Supercomputing, 2019, 75 : 5597 - 5621
  • [50] Robust Variational Autoencoders and Normalizing Flows for Unsupervised Network Anomaly Detection
    Najari, Naji
    Berlemont, Samuel
    Lefebvre, Gregoire
    Duffner, Stefan
    Garcia, Christophe
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 281 - 292