CBAM: A Contextual Model for Network Anomaly Detection

CBAM: A Contextual Model for Network Anomaly Detection
复制标题

DOI:
10.3390/computers10060079
复制
发表时间:
2021-06
期刊:
Comput.
影响因子:
--
通讯作者:
H. Clausen;G. Grov;David Aspinall
H. Clausen;G. Grov;David Aspinall
中科院分区:
其他
文献类型:
--
作者:
H. Clausen;G. Grov;David Aspinall

文献摘要

被引文献

相似文献

基于异常的入侵检测方法旨在对抗零日攻击的增长率,然而,它们的成功目前仅限于使用聚合流量特征检测大容量攻击。最近的评估表明,目前基于异常的网络入侵检测方法不能可靠地检测远程访问攻击。它们体积较小,通常只有与周围环境相比才能脱颖而出。目前,异常方法主要试图检测点异常的访问攻击事件,而忽略了它们出现的上下文。我们提出并研究了一种基于深度LSTM网络的上下文双向异常模型(CBAM),该模型专门用于检测上下文网络异常等攻击。该模型有效地学习网络流中的短期序列模式作为条件事件概率。访问攻击在利用漏洞时经常会打破这些模式,因此可以被检测为上下文异常。我们评估了CBAM上的三个数据集,提供了代表性的网络访问攻击,在很长的时间跨度,从现实世界的红队攻击的流量的现实生活中的流量。我们认为,这个程序集是更接近一个潜在的部署环境比目前的NIDS基准数据集。通过构建深度模型,我们能够将误报率降低到0.16%,同时有效检测七次访问攻击中的六次,这明显低于其他方法的操作范围。我们进一步证明,短期流结构在很长一段时间内保持稳定,使得CBAM对概念漂移具有鲁棒性。
Anomaly-based intrusion detection methods aim to combat the increasing rate of zero-day attacks, however, their success is currently restricted to the detection of high-volume attacks using aggregated traffic features. Recent evaluations show that the current anomaly-based network intrusion detection methods fail to reliably detect remote access attacks. These are smaller in volume and often only stand out when compared to their surroundings. Currently, anomaly methods try to detect access attack events mainly as point anomalies and neglect the context they appear in. We present and examine a contextual bidirectional anomaly model (CBAM) based on deep LSTM-networks that is specifically designed to detect such attacks as contextual network anomalies. The model efficiently learns short-term sequential patterns in network flows as conditional event probabilities. Access attacks frequently break these patterns when exploiting vulnerabilities, and can thus be detected as contextual anomalies. We evaluated CBAM on an assembly of three datasets that provide both representative network access attacks, real-life traffic over a long timespan, and traffic from a real-world red-team attack. We contend that this assembly is closer to a potential deployment environment than current NIDS benchmark datasets. We show that, by building a deep model, we are able to reduce the false positive rate to 0.16% while effectively detecting six out of seven access attacks, which is significantly lower than the operational range of other methods. We further demonstrate that short-term flow structures remain stable over long periods of time, making the CBAM robust against concept drift.