An LSTM-Based Deep Learning Approach for Classifying Malicious Traffic at the Packet Level

被引:85
|
作者
Hwang, Ren-Hung [1 ]
Peng, Min-Chun [1 ]
Van-Linh Nguyen [1 ]
Chang, Yu-Lun [1 ]
机构
[1] Natl Chung Cheng Univ, Dept Comp Sci & Informat Engn, Chiayi 62102, Taiwan
来源
APPLIED SCIENCES-BASEL | 2019年 / 9卷 / 16期
关键词
deep learning for network security; long short-term memory; malicious traffic classification; NETWORK;
D O I
10.3390/app9163414
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Recently, deep learning has been successfully applied to network security assessments and intrusion detection systems (IDSs) with various breakthroughs such as using Convolutional Neural Networks (CNN) and Long Short-Term Memory (LSTM) to classify malicious traffic. However, these state-of-the-art systems also face tremendous challenges to satisfy real-time analysis requirements due to the major delay of the flow-based data preprocessing, i.e., requiring time for accumulating the packets into particular flows and then extracting features. If detecting malicious traffic can be done at the packet level, detecting time will be significantly reduced, which makes the online real-time malicious traffic detection based on deep learning technologies become very promising. With the goal of accelerating the whole detection process by considering a packet level classification, which has not been studied in the literature, in this research, we propose a novel approach in building the malicious classification system with the primary support of word embedding and the LSTM model. Specifically, we propose a novel word embedding mechanism to extract packet semantic meanings and adopt LSTM to learn the temporal relation among fields in the packet header and for further classifying whether an incoming packet is normal or a part of malicious traffic. The evaluation results on ISCX2012, USTC-TFC2016, IoT dataset from Robert Gordon University and IoT dataset collected on our Mirai Botnet show that our approach is competitive to the prior literature which detects malicious traffic at the flow level. While the network traffic is booming year by year, our first attempt can inspire the research community to exploit the advantages of deep learning to build effective IDSs without suffering significant detection delay.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] OneHotEncoding and LSTM-based deep learning models for protein secondary structure prediction
    Vamsidhar Enireddy
    C. Karthikeyan
    D. Vijendra Babu
    Soft Computing, 2022, 26 : 3825 - 3836
  • [32] Digital beamforming enhancement with LSTM-based deep learning for millimeter wave transmission
    Naji, Ali A.
    Jamel, Thamer M.
    Khazaal, Hassan F.
    OPEN ENGINEERING, 2024, 14 (01):
  • [33] Enhancing Myocardial Infarction Diagnosis: LSTM-based Deep Learning Approach Integrating Echocardiographic Wall Motion Analysis
    Soe, Hsu Thiri
    Iwata, Hiroyasu
    JOURNAL OF MEDICAL AND BIOLOGICAL ENGINEERING, 2024, 44 (05) : 704 - 710
  • [34] MFFusion: A Multi-level Features Fusion Model for Malicious Traffic Detection based on Deep Learning
    Lin, Kunda
    Xu, Xiaolong
    Xiao, Fu
    COMPUTER NETWORKS, 2022, 202
  • [35] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Lotfollahi, Mohammad
    Siavoshani, Mahdi Jafari
    Zade, Ramin Shirali Hossein
    Saberian, Mohammdsadegh
    SOFT COMPUTING, 2020, 24 (03) : 1999 - 2012
  • [36] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Mohammad Lotfollahi
    Mahdi Jafari Siavoshani
    Ramin Shirali Hossein Zade
    Mohammdsadegh Saberian
    Soft Computing, 2020, 24 : 1999 - 2012
  • [37] An LSTM-Based Ensemble Learning Approach for Time-Dependent Reliability Analysis
    Li, Mingyang
    Wang, Zequn
    JOURNAL OF MECHANICAL DESIGN, 2021, 143 (03)
  • [38] LSTM-Based Recommendation Approach for Interaction Records
    Zhou, Yan
    Ushiama, Taketoshi
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM) 2019, 2019, 935 : 950 - 962
  • [39] A Hybrid Deep Learning Approach with GCN and LSTM for Traffic Flow Prediction
    Li, Zhishuai
    Xiong, Gang
    Chen, Yuanyuan
    Lv, Yisheng
    Hu, Bin
    Zhu, Fenghua
    Wang, Fei-Yue
    2019 IEEE INTELLIGENT TRANSPORTATION SYSTEMS CONFERENCE (ITSC), 2019, : 1929 - 1933
  • [40] The Method of Seed Based Grouping Malicious Traffic by Deep-Learning
    Baek, Ui-Jun
    Park, Jee-Tae
    Hasanova, Huru
    Kim, Myung-Sup
    2018 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2018, : 701 - 705