Frequency Domain Feature Based Robust Malicious Traffic Detection

被引:19
|
作者
Fu, Chuanpu [1 ]
Li, Qi [2 ,3 ,4 ]
Shen, Meng
Xu, Ke [1 ,2 ,4 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Beijing Natl Res Ctr Informat Sci & Technol BNRis, Beijing 100084, Peoples R China
[3] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing 100084, Peoples R China
[4] Zhongguancun Lab, Beijing 100094, Peoples R China
关键词
Feature extraction; Frequency-domain analysis; Throughput; Machine learning; Encoding; Data mining; Redundancy; Malicious traffic detection; machine learning; frequency domain; SERVICE ATTACKS; DDOS DEFENSE; NETWORK; TCP; CLASSIFICATION;
D O I
10.1109/TNET.2022.3195871
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning (ML) based malicious traffic detection is an emerging security paradigm, particularly for zero-day attack detection, which is complementary to existing rule based detection. However, the existing ML based detection achieves low detection accuracy and low throughput incurred by inefficient traffic features extraction. Thus, they cannot detect attacks in realtime, especially in high throughput networks. Particularly, these detection systems similar to the existing rule based detection can be easily evaded by sophisticated attacks. To this end, we propose, a realtime ML based malicious traffic detection system that achieves both high accuracy and high throughput by utilizing frequency domain features. It utilizes sequential information represented by the frequency domain features to achieve bounded information loss, which ensures high detection accuracy, and meanwhile constrains the scale of features to achieve high detection throughput. In particular, attackers cannot easily interfere with the frequency domain features and thus is robust against various evasion attacks. Our experiments with 74 types of attacks demonstrate that, compared with the state-of-the-art systems, can accurately detect various sophisticated and stealthy attacks, achieving at most 18.36% improvement of AUC, while achieving two orders of magnitude throughput. Even under various evasion attacks, is still able to maintain around 90% detection accuracy.
引用
收藏
页码:452 / 467
页数:16
相关论文
共 50 条
  • [21] A feature enhancement-based model for the malicious traffic detection with small-scale imbalanced dataset
    Wei, Nan
    Yin, Lihua
    Zhou, Xiaoming
    Ruan, Chuhong
    Wei, Yibo
    Luo, Xi
    Chang, Youyi
    Li, Zhao
    INFORMATION SCIENCES, 2023, 647
  • [22] Blacklist-based Malicious IP Traffic Detection
    Ghafir, Ibrahim
    Prenosil, Vaclav
    2015 GLOBAL CONFERENCE ON COMMUNICATION TECHNOLOGIES (GCCT), 2015, : 229 - 233
  • [23] Traffic-based Malicious Switch Detection in SDN
    Du, Xiaodong
    Wang, Ming-Zhong
    Zhang, Xiaoping
    Zhu, Liehuang
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (05): : 119 - 130
  • [24] Enhancing Detection of Malicious Traffic Through FPGA-Based Frequency Transformation and Machine Learning
    Hu, Zhenguo
    Hasegawa, Hirokazu
    Yamaguchi, Yukiko
    Shimada, Hajime
    IEEE ACCESS, 2024, 12 : 2648 - 2659
  • [25] IoT Malicious Traffic Detection Based on Federated Learning
    Shen, Yi
    Zhang, Yuhan
    Li, Yuwei
    Ding, Wanmeng
    Hu, Miao
    Li, Yang
    Huang, Cheng
    Wang, Jie
    DIGITAL FORENSICS AND CYBER CRIME, PT 1, ICDF2C 2023, 2024, 570 : 249 - 263
  • [26] Research on malicious traffic detection based on image recognition
    Li, Wei
    Chen, Yuliang
    Zhao, Lixin
    Luo, Yazhou
    Liu, Xin
    INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2023, 16 (02) : 134 - 142
  • [27] Suboptimal Feature Selection Techniques for Effective Malicious Traffic Detection on Lightweight Devices
    Jeon, So-Eun
    Oh, Ye-Sol
    Lee, Yeon-Ji
    Lee, Il-Gu
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2024, 140 (02): : 1669 - 1687
  • [28] FAFS: A Fuzzy Association Feature Selection Method for Network Malicious Traffic Detection
    Feng, Yongxin
    Kang, Yingyun
    Zhang, Hao
    Zhang, Wenbo
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2020, 14 (01): : 240 - 259
  • [29] Robust Feature Selection and Robust PCA for Internet Traffic Anomaly Detection
    Pascoal, Claudia
    Rosario de Oliveira, M.
    Valadas, Rui
    Filzmoser, Peter
    Salvador, Paulo
    Pacheco, Antonio
    2012 PROCEEDINGS IEEE INFOCOM, 2012, : 1755 - 1763
  • [30] Malicious Web Page Detection Based on Feature Classification
    Phakoontod, Chanachai
    Limthanmaphon, Benchaphon
    2012 7TH INTERNATIONAL CONFERENCE ON COMPUTING AND CONVERGENCE TECHNOLOGY (ICCCT2012), 2012, : 66 - 71