Unsupervised Protocol-based Intrusion Detection for Real-world Networks

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Anomaly-based Intrusion Detection Systems (IDSs) are rarely deployed in real networks, because of their high false positive rate. Their ability to detect unknown attacks is, however, very valuable in a context where new threats are emerging almost daily. This paper presents an unsupervised anomaly-based intrusion detection solution focused on protocol headers analysis. This approach is tested on a recent and realistic dataset (CICIDS2017) over a 4-day period. Each protocol is converted to a set of normalized numeric features, which are processed by 5 neural network architectures: deep autoencoders, deep MLPs, LSTMs, BiLSTMs, and GANs. The output of these algorithms is an anomaly score, which is normalized and combined with the anomaly scores of other protocols. We argue that this classification problem is very different from the actual problem of intrusion detection and requires new metrics. In particular, packet anomaly scores must be refined in a post-processing step to aggregate anomalies into continuous attacks. This approach successfully detects 7 out of 11 attacks not seen during the training phase, without any false positives. It is thus possible to consider deployments in real-world networks of such IDSs, capable of reliably detecting zero-day attacks.

Original languageEnglish
Title of host publication2020 International Conference on Computing, Networking and Communications, ICNC 2020
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages299-303
Number of pages5
ISBN (Electronic)9781728149059
DOIs
Publication statusPublished - 1 Feb 2020
Externally publishedYes
Event2020 International Conference on Computing, Networking and Communications, ICNC 2020 - Big Island, United States
Duration: 17 Feb 202020 Feb 2020

Publication series

Name2020 International Conference on Computing, Networking and Communications, ICNC 2020

Conference

Conference2020 International Conference on Computing, Networking and Communications, ICNC 2020
Country/TerritoryUnited States
CityBig Island
Period17/02/2020/02/20

Keywords

  • CICIDS2017
  • Intrusion detection
  • Neural networks
  • Unsupervised learning

Fingerprint

Dive into the research topics of 'Unsupervised Protocol-based Intrusion Detection for Real-world Networks'. Together they form a unique fingerprint.

Cite this