Detecting zero-day attacks using context-aware anomaly detection at the application-layer

被引:42
|
作者
Duessel, Patrick [1 ]
Gehl, Christian [2 ]
Flegel, Ulrich [3 ]
Dietrich, Sven [4 ]
Meier, Michael [1 ]
机构
[1] Univ Bonn, Inst Comp Sci 4, Friedrich Ebert Allee 144, D-53113 Bonn, Germany
[2] Trifense GmbH Intelligent Network Def, Germendorfer Str 79, D-16727 Velten, Germany
[3] Infineon Technol AG, Campeon 1-12, D-86579 Neubiberg, Germany
[4] CUNY John Jay Coll Criminal Justice, Math & Comp Sci Dept, 524 West 59th St, New York, NY 10019 USA
关键词
Intrusion detection; Machine learning; Anomaly detection; Protocol analysis; Deep packet inspection;
D O I
10.1007/s10207-016-0344-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection allows for the identification of unknown and novel attacks in network traffic. However, current approaches for anomaly detection of network packet payloads are limited to the analysis of plain byte sequences. Experiments have shown that application-layer attacks become difficult to detect in the presence of attack obfuscation using payload customization. The ability to incorporate syntactic context into anomaly detection provides valuable information and increases detection accuracy. In this contribution, we address the issue of incorporating protocol context into payload-based anomaly detection. We present a new data representation, called -grams, that allows to integrate syntactic and sequential features of payloads in an unified feature space and provides the basis for context-aware detection of network intrusions. We conduct experiments on both text-based and binary application-layer protocols which demonstrate superior accuracy on the detection of various types of attacks over regular anomaly detection methods. Furthermore, we show how -grams can be used to interpret detected anomalies and thus, provide explainable decisions in practice.
引用
收藏
页码:475 / 490
页数:16
相关论文
共 50 条
  • [1] Detecting zero-day attacks using context-aware anomaly detection at the application-layer
    Patrick Duessel
    Christian Gehl
    Ulrich Flegel
    Sven Dietrich
    Michael Meier
    International Journal of Information Security, 2017, 16 : 475 - 490
  • [2] Detecting and Analyzing Zero-day Attacks using Honeypots
    Musca, Constantin
    Mirica, Emma
    Deaconescu, Razvan
    19TH INTERNATIONAL CONFERENCE ON CONTROL SYSTEMS AND COMPUTER SCIENCE (CSCS 2013), 2013, : 543 - 548
  • [3] A Contextual Anomaly Detection Approach to Discover Zero-Day Attacks
    AlEroud, Ahmed
    Karabatis, George
    2012 ASE INTERNATIONAL CONFERENCE ON CYBER SECURITY (CYBERSECURITY), 2012, : 40 - 45
  • [4] Anomaly Detection of Zero-Day Attacks Based on CNN and Regularization Techniques
    Ibrahim Hairab, Belal
    Aslan, Heba K.
    Elsayed, Mahmoud Said
    Jurcut, Anca D.
    Azer, Marianne A.
    ELECTRONICS, 2023, 12 (03)
  • [5] Detection of Zero-day Attacks on IoT
    Reardon, Shay
    Hssayeni, Murtadha D.
    Mahgoub, Imadeldin
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [6] Application-layer context-aware services for pervasive computing environments
    Kung, Hsu-Yang
    Lin, Ching-Yu
    ICICIC 2006: FIRST INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING, INFORMATION AND CONTROL, VOL 3, PROCEEDINGS, 2006, : 229 - +
  • [7] Detecting Application-layer Attacks Based on User's Application-layer Behaviors
    Xie, Bailin
    Jiang, Shengyi
    INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY II, PTS 1-4, 2013, 411-414 : 607 - 612
  • [8] Application-layer Anomaly Detection Based on Application-layer Protocols' Keywords
    Xie, Bailin
    Zhang, Qiansheng
    PROCEEDINGS OF 2012 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2012), 2012, : 2131 - 2135
  • [9] Detection of zero-day attacks in computer networks using combined classification
    Gavari Bami, Hamid
    Moharamkhani, Elaheh
    Zadmehr, Behrouz
    Najafpoor, Vahid
    Shokouhifar, Mohammad
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (27):
  • [10] Context-Aware Anomaly Detection Using Vehicle Dynamics
    Chen, Chun-Yu
    Shin, Kang G.
    Dadras, Soodeh
    PROCEEDINGS OF 27TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2024, 2024, : 531 - 545