Network Anomaly Detection Using Memory-Augmented Deep Autoencoder

被引:46
|
作者
Min, Byeongjun [1 ]
Yoo, Jihoon [2 ]
Kim, Sangsoo [3 ]
Shin, Dongil [2 ]
Shin, Dongkyoo [2 ]
机构
[1] Sejong Univ, Convergence Engn Intelligent Drones, Dept Comp Engn, Seoul 05006, South Korea
[2] Sejong Univ, Dept Comp Engn, Seoul 05006, South Korea
[3] Agcy Def Dev, Daejeon 05600, South Korea
关键词
Decoding; Anomaly detection; Network intrusion detection; Data models; Memory modules; Mathematical model; Machine learning; autoencoder; anomaly detection; memory-augmented autoencoder; INTRUSION DETECTION;
D O I
10.1109/ACCESS.2021.3100087
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, attacks on network environments continue to rapidly advance and are increasingly intelligent. Accordingly, it is evident that there are limitations in existing signature-based intrusion detection systems. In particular, for novel attacks such as Advanced Persistent Threat (APT), signature patterns have problems with poor generalization performance. Furthermore, in a network environment, attack samples are rarely collected compared to normal samples, creating the problem of imbalanced data. Anomaly detection using an autoencoder has been widely studied in this environment, and learning is through semi-supervised learning methods to overcome these problems. This approach is based on the assumption that reconstruction errors for samples that are not used for training will be large, but an autoencoder is often over-generalized and this assumption is often broken. In this paper, we propose a network intrusion detection method using a memory-augmented deep auto-encoder (MemAE) that can solve the over-generalization problem of autoencoders. The MemAE model is trained to reconstruct the input of an abnormal sample that is close to a normal sample, which solves the generalization problem for such abnormal samples. Experiments were conducted on the NSL-KDD, UNSW-NB15, and CICIDS 2017 datasets, and it was confirmed that the proposed method is better than other one-class models.
引用
收藏
页码:104695 / 104706
页数:12
相关论文
共 50 条
  • [1] Memorizing Normality to Detect Anomaly: Memory-augmented Deep Autoencoder for Unsupervised Anomaly Detection
    Gong, Dong
    Liu, Lingqiao
    Le, Vuong
    Saha, Budhaditya
    Mansour, Moussa Reda
    Venkatesh, Svetha
    van den Hengel, Anton
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 1705 - 1714
  • [2] Anomaly Detection With Memory-Augmented Adversarial Autoencoder Networks for Industry 5.0
    Zhang, Huan
    Kumar, Neeraj
    Wu, Sheng
    Wu, Chunlei
    Wang, Jian
    Zhang, Peiying
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 1952 - 1962
  • [3] A Cognitive Memory-Augmented Network for Visual Anomaly Detection
    Wang, Tian
    Xu, Xing
    Shen, Fumin
    Yang, Yang
    IEEE-CAA JOURNAL OF AUTOMATICA SINICA, 2021, 8 (07) : 1296 - 1307
  • [4] Research on Video Anomaly Detection Based on Cascaded Memory-augmented Autoencoder
    Zhang, Lin
    Chen, Zhao-Bo
    Ma, Xiao-Xuan
    Zhang, Fan-Bo
    Li, Ze-Hui
    Shan, Xian-Ying
    Journal of Computers (Taiwan), 2023, 34 (05) : 229 - 241
  • [5] A Cognitive Memory-Augmented Network for Visual Anomaly Detection
    Tian Wang
    Xing Xu
    Fumin Shen
    Yang Yang
    IEEE/CAAJournalofAutomaticaSinica, 2021, 8 (07) : 1296 - 1307
  • [6] Anomaly detection in concrete dam using memory-augmented autoencoder and generative adversarial network (MemAE-GAN)
    Kang, Xinyu
    Li, Yanlong
    Zhang, Ye
    Ma, Ning
    Wen, Lifeng
    AUTOMATION IN CONSTRUCTION, 2024, 168
  • [7] Memory-Augmented Autoencoder With Adaptive Reconstruction and Sample Attribution Mining for Hyperspectral Anomaly Detection
    Huo, Yu
    Cheng, Xi
    Lin, Sheng
    Zhang, Min
    Wang, Hai
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 18
  • [8] Memory-augmented appearance-motion network for video anomaly detection
    Wang, Le
    Tian, Junwen
    Zhou, Sanping
    Shi, Haoyue
    Hua, Gang
    PATTERN RECOGNITION, 2023, 138
  • [9] Variable Speed Bearing Anomaly Detection via Order Tracking and Cascaded Memory-Augmented Autoencoder
    Lu, Ruonan
    Yang, Qinmin
    Zheng, Da
    Cao, Weiwei
    Chen, Xu
    Li, Chao
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2025, 74
  • [10] TSMAE: A Novel Anomaly Detection Approach for Internet of Things Time Series Data Using Memory-Augmented Autoencoder
    Gao, Honghao
    Qiu, Binyang
    Barroso, Ramon J. Duran
    Hussain, Walayat
    Xu, Yueshen
    Wang, Xinheng
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2023, 10 (05): : 2978 - 2990