An LSTM-Based Deep Learning Approach for Classifying Malicious Traffic at the Packet Level

被引:85
|
作者
Hwang, Ren-Hung [1 ]
Peng, Min-Chun [1 ]
Van-Linh Nguyen [1 ]
Chang, Yu-Lun [1 ]
机构
[1] Natl Chung Cheng Univ, Dept Comp Sci & Informat Engn, Chiayi 62102, Taiwan
来源
APPLIED SCIENCES-BASEL | 2019年 / 9卷 / 16期
关键词
deep learning for network security; long short-term memory; malicious traffic classification; NETWORK;
D O I
10.3390/app9163414
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Recently, deep learning has been successfully applied to network security assessments and intrusion detection systems (IDSs) with various breakthroughs such as using Convolutional Neural Networks (CNN) and Long Short-Term Memory (LSTM) to classify malicious traffic. However, these state-of-the-art systems also face tremendous challenges to satisfy real-time analysis requirements due to the major delay of the flow-based data preprocessing, i.e., requiring time for accumulating the packets into particular flows and then extracting features. If detecting malicious traffic can be done at the packet level, detecting time will be significantly reduced, which makes the online real-time malicious traffic detection based on deep learning technologies become very promising. With the goal of accelerating the whole detection process by considering a packet level classification, which has not been studied in the literature, in this research, we propose a novel approach in building the malicious classification system with the primary support of word embedding and the LSTM model. Specifically, we propose a novel word embedding mechanism to extract packet semantic meanings and adopt LSTM to learn the temporal relation among fields in the packet header and for further classifying whether an incoming packet is normal or a part of malicious traffic. The evaluation results on ISCX2012, USTC-TFC2016, IoT dataset from Robert Gordon University and IoT dataset collected on our Mirai Botnet show that our approach is competitive to the prior literature which detects malicious traffic at the flow level. While the network traffic is booming year by year, our first attempt can inspire the research community to exploit the advantages of deep learning to build effective IDSs without suffering significant detection delay.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Deep Learning for Classifying Malicious Network Traffic
    Millar, K.
    Cheng, A.
    Chew, H. G.
    Lim, C-C
    TRENDS AND APPLICATIONS IN KNOWLEDGE DISCOVERY AND DATA MINING: PAKDD 2018 WORKSHOPS, 2018, 11154 : 156 - 161
  • [2] Short-Term Traffic Forecasting using LSTM-based Deep Learning Models
    Haputhanthri, Dilantha
    Wijayasiri, Adeesha
    MORATUWA ENGINEERING RESEARCH CONFERENCE (MERCON 2021) / 7TH INTERNATIONAL MULTIDISCIPLINARY ENGINEERING RESEARCH CONFERENCE, 2021, : 602 - 607
  • [3] A deep learning LSTM-based approach for AMD classification using OCT images
    Hamid, Laila
    Elnokrashy, Amgad
    Abdelhay, Ehab H.
    Abdelsalam, Mohamed M.
    Neural Computing and Applications, 2024, 36 (31) : 19531 - 19547
  • [4] A Deep Hierarchical Network for Packet-Level Malicious Traffic Detection
    Wang, Bo
    Su, Yang
    Zhang, Mingshu
    Nie, Junke
    IEEE ACCESS, 2020, 8 : 201728 - 201740
  • [5] A CNN and LSTM-based approach to classifying transient radio frequency interference
    Czech, D.
    Mishra, A.
    Inggs, M.
    ASTRONOMY AND COMPUTING, 2018, 25 : 52 - 57
  • [6] LSTM-based Deep Learning Models for Answer Ranking
    Li, Zhenzhen
    Huang, Jiuming
    Zhou, Zhongcheng
    Zhang, Haoyu
    Chang, Shoufeng
    Huang, Zhijie
    2016 IEEE FIRST INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC 2016), 2016, : 90 - 97
  • [7] Deep reinforcement learning for base station switching scheme with federated LSTM-based traffic predictions
    Park, Hyebin
    Yoon, Seung Hyun
    ETRI JOURNAL, 2024, 46 (03) : 379 - 391
  • [8] An LSTM-based Deep Learning Approach with Application to Predicting Hospital Emergency Department Admissions
    Kadri, Farid
    Baraoui, Merouane
    Nouaouri, Issam
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND SYSTEMS MANAGEMENT (IESM 2019), 2019, : 13 - 18
  • [9] A novel approach to fake news classification using LSTM-based deep learning models
    Padalko, Halyna
    Chomko, Vasyl
    Chumachenko, Dmytro
    FRONTIERS IN BIG DATA, 2024, 6
  • [10] Predicting the lateral displacement of tall buildings using an LSTM-based deep learning approach
    Kim, Bubryur
    Preethaa, K. R. Sri
    Chen, Zengshun
    Natarajan, Yuvaraj
    Wadhwa, Gitanjali
    Lee, Hong Min
    WIND AND STRUCTURES, 2023, 36 (06) : 379 - 392