An LSTM-Based Deep Learning Approach for Classifying Malicious Traffic at the Packet Level

被引:85
|
作者
Hwang, Ren-Hung [1 ]
Peng, Min-Chun [1 ]
Van-Linh Nguyen [1 ]
Chang, Yu-Lun [1 ]
机构
[1] Natl Chung Cheng Univ, Dept Comp Sci & Informat Engn, Chiayi 62102, Taiwan
来源
APPLIED SCIENCES-BASEL | 2019年 / 9卷 / 16期
关键词
deep learning for network security; long short-term memory; malicious traffic classification; NETWORK;
D O I
10.3390/app9163414
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Recently, deep learning has been successfully applied to network security assessments and intrusion detection systems (IDSs) with various breakthroughs such as using Convolutional Neural Networks (CNN) and Long Short-Term Memory (LSTM) to classify malicious traffic. However, these state-of-the-art systems also face tremendous challenges to satisfy real-time analysis requirements due to the major delay of the flow-based data preprocessing, i.e., requiring time for accumulating the packets into particular flows and then extracting features. If detecting malicious traffic can be done at the packet level, detecting time will be significantly reduced, which makes the online real-time malicious traffic detection based on deep learning technologies become very promising. With the goal of accelerating the whole detection process by considering a packet level classification, which has not been studied in the literature, in this research, we propose a novel approach in building the malicious classification system with the primary support of word embedding and the LSTM model. Specifically, we propose a novel word embedding mechanism to extract packet semantic meanings and adopt LSTM to learn the temporal relation among fields in the packet header and for further classifying whether an incoming packet is normal or a part of malicious traffic. The evaluation results on ISCX2012, USTC-TFC2016, IoT dataset from Robert Gordon University and IoT dataset collected on our Mirai Botnet show that our approach is competitive to the prior literature which detects malicious traffic at the flow level. While the network traffic is booming year by year, our first attempt can inspire the research community to exploit the advantages of deep learning to build effective IDSs without suffering significant detection delay.
引用
收藏
页数:14
相关论文
共 50 条
  • [41] Deep attributes: innovative LSTM-based seismic attributes
    Roncoroni, G.
    Forte, E.
    Pipan, M.
    GEOPHYSICAL JOURNAL INTERNATIONAL, 2024, 237 (01) : 378 - 388
  • [42] Detecting the backfill pipeline blockage and leakage through an LSTM-based deep learning model
    Bolin Xiao
    Shengjun Miao
    Daohong Xia
    Huatao Huang
    Jingyu Zhang
    International Journal of Minerals, Metallurgy and Materials, 2023, 30 : 1573 - 1583
  • [43] Detecting the backfill pipeline blockage and leakage through an LSTM-based deep learning model
    Xiao, Bolin
    Miao, Shengjun
    Xia, Daohong
    Huang, Huatao
    Zhang, Jingyu
    INTERNATIONAL JOURNAL OF MINERALS METALLURGY AND MATERIALS, 2023, 30 (08) : 1573 - 1583
  • [44] VDS Data-Based Deep Learning Approach for Traffic Forecasting Using LSTM Network
    Yi, Hongsuk
    Bui, Khac-Hoai Nam
    PROGRESS IN ARTIFICIAL INTELLIGENCE, EPIA 2019, PT I, 2019, 11804 : 547 - 558
  • [45] LSTM-Based Neural Network to Recognize Human Activities Using Deep Learning Techniques
    Sabbu, Sunitha
    Ganesan, Vithya
    APPLIED COMPUTATIONAL INTELLIGENCE AND SOFT COMPUTING, 2022, 2022
  • [46] Detecting the backfill pipeline blockage and leakage through an LSTM-based deep learning model
    Bolin Xiao
    Shengjun Miao
    Daohong Xia
    Huatao Huang
    Jingyu Zhang
    InternationalJournalofMinerals,MetallurgyandMaterials, 2023, (08) : 1573 - 1583
  • [47] LSTM-based deep learning application in brain tumor detection using MR spectroscopy
    Altun, Sinan
    Alkan, Ahmet
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2023, 38 (02): : 1193 - 1202
  • [48] LSTM-Based Deep Learning Models for Long-Term Tourism Demand Forecasting
    Salamanis, Athanasios
    Xanthopoulou, Georgia
    Kehagias, Dionysios
    Tzovaras, Dimitrios
    ELECTRONICS, 2022, 11 (22)
  • [49] Hybrid compression for LSTM-based encrypted traffic classification model
    Mu Q.
    Zhang M.
    International Journal of Wireless and Mobile Computing, 2024, 26 (01) : 61 - 73
  • [50] A hybrid GRU and LSTM-based deep learning approach for multiclass structural damage identification using dynamic acceleration data
    Das, Tanmay
    Guchhait, Shyamal
    ENGINEERING FAILURE ANALYSIS, 2025, 170