Detecting zero-day attacks using context-aware anomaly detection at the application-layer

被引:42
|
作者
Duessel, Patrick [1 ]
Gehl, Christian [2 ]
Flegel, Ulrich [3 ]
Dietrich, Sven [4 ]
Meier, Michael [1 ]
机构
[1] Univ Bonn, Inst Comp Sci 4, Friedrich Ebert Allee 144, D-53113 Bonn, Germany
[2] Trifense GmbH Intelligent Network Def, Germendorfer Str 79, D-16727 Velten, Germany
[3] Infineon Technol AG, Campeon 1-12, D-86579 Neubiberg, Germany
[4] CUNY John Jay Coll Criminal Justice, Math & Comp Sci Dept, 524 West 59th St, New York, NY 10019 USA
关键词
Intrusion detection; Machine learning; Anomaly detection; Protocol analysis; Deep packet inspection;
D O I
10.1007/s10207-016-0344-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection allows for the identification of unknown and novel attacks in network traffic. However, current approaches for anomaly detection of network packet payloads are limited to the analysis of plain byte sequences. Experiments have shown that application-layer attacks become difficult to detect in the presence of attack obfuscation using payload customization. The ability to incorporate syntactic context into anomaly detection provides valuable information and increases detection accuracy. In this contribution, we address the issue of incorporating protocol context into payload-based anomaly detection. We present a new data representation, called -grams, that allows to integrate syntactic and sequential features of payloads in an unified feature space and provides the basis for context-aware detection of network intrusions. We conduct experiments on both text-based and binary application-layer protocols which demonstrate superior accuracy on the detection of various types of attacks over regular anomaly detection methods. Furthermore, we show how -grams can be used to interpret detected anomalies and thus, provide explainable decisions in practice.
引用
收藏
页码:475 / 490
页数:16
相关论文
共 50 条
  • [41] Social Media Zero-Day Attack Detection Using TensorFlow
    Topcu, Ahmet Ercan
    Alzoubi, Yehia Ibrahim
    Elbasi, Ersin
    Camalan, Emre
    ELECTRONICS, 2023, 12 (17)
  • [42] Real-Time Detection of Distributed Zero-Day Attacks in ad hoc Networks
    Cannady, James
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2010, : 72 - 81
  • [43] An adaptable deep learning-based intrusion detection system to zero-day attacks
    Soltani, Mahdi
    Ousat, Behzad
    Siavoshani, Mahdi Jafari
    Jahangir, Amir Hossein
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 76
  • [44] A Zero-Shot Learning-Based Detection Model Against Zero-Day Attacks in IoT
    Gao, Xueqin
    Chen, Kai
    Zhao, Yufei
    Zhang, Peng
    Han, Longxi
    Zhang, Daojuan
    2024 9TH INTERNATIONAL CONFERENCE ON ELECTRONIC TECHNOLOGY AND INFORMATION SCIENCE, ICETIS 2024, 2024, : 309 - 314
  • [45] A Novel Framework for Zero-Day Attacks Detection and Response with Cyberspace Mimic Defense Architecture
    Liu, Wenyan
    Chen, Fucai
    Hu, Hongchao
    Cheng, Guozhen
    Huo, Shumin
    Liang, Hao
    2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2017, : 50 - 53
  • [46] Zero-Day Malware Classification and Detection Using Machine Learning
    Kumar J.
    Rajendran B.
    Sudarsan S.D.
    SN Computer Science, 5 (1)
  • [47] Federated Incremental Learning based Evolvable Intrusion Detection System for Zero-Day Attacks
    Jin, Dong
    Chen, Shuangwu
    He, Huasen
    Jiang, Xiaofeng
    Cheng, Siyu
    Yang, Jian
    IEEE NETWORK, 2023, 37 (01): : 125 - 132
  • [48] Information System Security Reinforcement with WGAN-GP for Detection of Zero-Day Attacks
    Mu, Ziyu
    Shi, Xiyu
    Dogan, Safak
    2024 7TH INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND BIG DATA, ICAIBD 2024, 2024, : 105 - 110
  • [49] A Brief Review of Unsupervised Learning Algorithms for Zero-Day Attacks in Intrusion Detection Systems
    Oluwadare, Sunkanmi
    ElSayed, Zag
    Adekoya, Oluwaseun
    2024 IEEE 3RD INTERNATIONAL CONFERENCE ON COMPUTING AND MACHINE INTELLIGENCE, ICMI 2024, 2024,
  • [50] ZeroWall: Detecting Zero-Day Web Attacks through Encoder-Decoder Recurrent Neural Networks
    Tang, Ruming
    Yang, Zheng
    Li, Zeyan
    Meng, Weibin
    Wang, Haixin
    Li, Qi
    Sun, Yongqian
    Pei, Dan
    Wei, Tao
    Xu, Yanfei
    Liu, Yan
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2020, : 2479 - 2488