Detecting zero-day attacks using context-aware anomaly detection at the application-layer

被引:42
|
作者
Duessel, Patrick [1 ]
Gehl, Christian [2 ]
Flegel, Ulrich [3 ]
Dietrich, Sven [4 ]
Meier, Michael [1 ]
机构
[1] Univ Bonn, Inst Comp Sci 4, Friedrich Ebert Allee 144, D-53113 Bonn, Germany
[2] Trifense GmbH Intelligent Network Def, Germendorfer Str 79, D-16727 Velten, Germany
[3] Infineon Technol AG, Campeon 1-12, D-86579 Neubiberg, Germany
[4] CUNY John Jay Coll Criminal Justice, Math & Comp Sci Dept, 524 West 59th St, New York, NY 10019 USA
关键词
Intrusion detection; Machine learning; Anomaly detection; Protocol analysis; Deep packet inspection;
D O I
10.1007/s10207-016-0344-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection allows for the identification of unknown and novel attacks in network traffic. However, current approaches for anomaly detection of network packet payloads are limited to the analysis of plain byte sequences. Experiments have shown that application-layer attacks become difficult to detect in the presence of attack obfuscation using payload customization. The ability to incorporate syntactic context into anomaly detection provides valuable information and increases detection accuracy. In this contribution, we address the issue of incorporating protocol context into payload-based anomaly detection. We present a new data representation, called -grams, that allows to integrate syntactic and sequential features of payloads in an unified feature space and provides the basis for context-aware detection of network intrusions. We conduct experiments on both text-based and binary application-layer protocols which demonstrate superior accuracy on the detection of various types of attacks over regular anomaly detection methods. Furthermore, we show how -grams can be used to interpret detected anomalies and thus, provide explainable decisions in practice.
引用
收藏
页码:475 / 490
页数:16
相关论文
共 50 条
  • [31] Zero-Day Attack Detection using Ensemble Technique
    Wangde, Fawaz, I
    Mulay, Shivam P.
    Adhao, Rahul B.
    Pachghare, Vinod K.
    INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING, 2021, 12 (05): : 551 - 557
  • [32] Comparative Evaluation of AI-Based Techniques for Zero-Day Attacks Detection
    Ali, Shamshair
    Rehman, Saif Ur
    Imran, Azhar
    Adeem, Ghazif
    Iqbal, Zafar
    Kim, Ki-Il
    ELECTRONICS, 2022, 11 (23)
  • [33] Zero-Query Transfer Attacks on Context-Aware Object Detectors
    Cai, Zikui
    Rane, Shantanu
    Brito, Alejandro E.
    Song, Chengyu
    Krishnamurthy, Srikanth, V
    Roy-Chowdhury, Amit K.
    Asif, M. Salman
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15004 - 15014
  • [34] UGRansome1819: A Novel Dataset for Anomaly Detection and Zero-Day Threats
    Nkongolo, Mike
    van Deventer, Jacobus Philippus
    Kasongo, Sydney Mambwe
    INFORMATION, 2021, 12 (10)
  • [35] A Systematic Literature Review on AI-Based Methods and Challenges in Detecting Zero-Day Attacks
    Yee Por, Lip
    Dai, Zhen
    Juan Leem, Siew
    Chen, Yi
    Yang, Jing
    Binbeshr, Farid
    Yuen Phan, Koo
    Soon Ku, Chin
    IEEE ACCESS, 2024, 12 : 144150 - 144163
  • [36] Context-aware Anomaly Detector for Monitoring Cyber Attacks on Automotive CAN Bus
    Kalutarage, Harsha Kumara
    Al-Kadri, M. Omar
    Cheah, Madeline
    Madzudzo, Garikayi
    ACM COMPUTER SCIENCE IN CARS SYMPOSIUM (CSCS 2019), 2019,
  • [37] Adaptive Context-Aware Distillation for Industrial Image Anomaly Detection
    He, Yuan
    Yang, Hua
    Yin, Zhouping
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2024, 73 : 1 - 15
  • [38] Anomaly Detection and Explanation in Context-Aware Software Product Lines
    Mauro, Jacopo
    Nieke, Michael
    Seidl, Christoph
    Yu, Ingrid Chieh
    21ST INTERNATIONAL SYSTEM & SOFTWARE PRODUCT LINE CONFERENCE (SPLC 2017), VOL 2, 2017, : 18 - 21
  • [39] Interactive Context-Aware Anomaly Detection Guided by User Feedback
    Shi, Yang
    Xu, Maoran
    Zhao, Rongwen
    Fu, Hao
    Wu, Tongshuang
    Cao, Nan
    IEEE TRANSACTIONS ON HUMAN-MACHINE SYSTEMS, 2019, 49 (06) : 550 - 559
  • [40] Context-aware Domain Adaptation for Time Series Anomaly Detection
    Lai, Kwei-Herng
    Wang, Lan
    Chen, Huiyuan
    Zhou, Kaixiong
    Wang, Fei
    Yang, Hao
    Hu, Xia
    PROCEEDINGS OF THE 2023 SIAM INTERNATIONAL CONFERENCE ON DATA MINING, SDM, 2023, : 676 - 684