Frequency Domain Feature Based Robust Malicious Traffic Detection

被引:18
|
作者
Fu, Chuanpu [1 ]
Li, Qi [2 ,3 ,4 ]
Shen, Meng
Xu, Ke [1 ,2 ,4 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Beijing Natl Res Ctr Informat Sci & Technol BNRis, Beijing 100084, Peoples R China
[3] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing 100084, Peoples R China
[4] Zhongguancun Lab, Beijing 100094, Peoples R China
关键词
Feature extraction; Frequency-domain analysis; Throughput; Machine learning; Encoding; Data mining; Redundancy; Malicious traffic detection; machine learning; frequency domain; SERVICE ATTACKS; DDOS DEFENSE; NETWORK; TCP; CLASSIFICATION;
D O I
10.1109/TNET.2022.3195871
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning (ML) based malicious traffic detection is an emerging security paradigm, particularly for zero-day attack detection, which is complementary to existing rule based detection. However, the existing ML based detection achieves low detection accuracy and low throughput incurred by inefficient traffic features extraction. Thus, they cannot detect attacks in realtime, especially in high throughput networks. Particularly, these detection systems similar to the existing rule based detection can be easily evaded by sophisticated attacks. To this end, we propose, a realtime ML based malicious traffic detection system that achieves both high accuracy and high throughput by utilizing frequency domain features. It utilizes sequential information represented by the frequency domain features to achieve bounded information loss, which ensures high detection accuracy, and meanwhile constrains the scale of features to achieve high detection throughput. In particular, attackers cannot easily interfere with the frequency domain features and thus is robust against various evasion attacks. Our experiments with 74 types of attacks demonstrate that, compared with the state-of-the-art systems, can accurately detect various sophisticated and stealthy attacks, achieving at most 18.36% improvement of AUC, while achieving two orders of magnitude throughput. Even under various evasion attacks, is still able to maintain around 90% detection accuracy.
引用
收藏
页码:452 / 467
页数:16
相关论文
共 50 条
  • [1] Realtime Robust Malicious Traffic Detection via Frequency Domain Analysis
    Fu, Chuanpu
    Li, Qi
    Shen, Meng
    Xu, Ke
    CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 3431 - 3446
  • [2] Malicious Domain Detection Based on Traffic Similarity
    Hu, Jianping
    Wang, Yongyi
    Shi, Fan
    Xu, Chengxi
    2ND INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING, INFORMATION SCIENCE AND INTERNET TECHNOLOGY, CII 2017, 2017, : 416 - 421
  • [3] REDA: Malicious Traffic Detection Based on Record Length and Frequency Domain Analysis
    Lin, Wanshuang
    Xia, Chunhe
    Wang, Tianbo
    Chen, Chen
    Zhao, Yuan
    Zhou, Weidong
    2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, : 668 - 675
  • [4] Robust Malicious Domain Detection
    Hason, Nitay
    Dvir, Amit
    Hajaj, Chen
    CYBER SECURITY CRYPTOGRAPHY AND MACHINE LEARNING (CSCML 2020), 2020, 12161 : 45 - 61
  • [5] DDOFM: Dynamic malicious domain detection method based on feature mining
    Wang H.
    Tang Z.
    Li H.
    Zhang J.
    Cai C.
    Computers and Security, 2023, 130
  • [6] ECNet: Robust Malicious Network Traffic Detection With Multi-View Feature and Confidence Mechanism
    Han, Xueying
    Liu, Song
    Liu, Junrong
    Jiang, Bo
    Lu, Zhigang
    Liu, Baoxu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6871 - 6885
  • [7] FEPDF: A Robust Feature Extractor for Malicious PDF Detection
    Li, Min
    Liu, Yunzheng
    Yu, Min
    Li, Gang
    Wang, Yongjian
    Liu, Chao
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 218 - 224
  • [8] An Adaptive Malicious Domain Detection Mechanism with DNS Traffic
    ShuoXu
    Li, ShuQin
    Meng, Kun
    Wu, LiJun
    Ding, Meng
    PROCEEDINGS OF 2017 VI INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2017), 2017, : 86 - 91
  • [9] Malicious Domain Names Detection Algorithm Based on Lexical Analysis and Feature Quantification
    Zhao, Hong
    Chang, Zhaobin
    Wang, Weijie
    Zeng, Xiangyan
    IEEE ACCESS, 2019, 7 : 128990 - 128999
  • [10] In-Network ML Feature Computation for Malicious Traffic Detection
    Amado, Joao R.
    Pereira, Francisco
    Signorello, Salvatore
    Correia, Miguel
    Ramos, Fernando M. V.
    PROCEEDINGS OF THE 2023 ACM SIGCOMM 2023 CONFERENCE, SIGCOMM 2023, 2023, : 1105 - 1107