Real-Time Evasion Attacks against Deep Learning-Based Anomaly Detection from Distributed System Logs

Real-Time Evasion Attacks against Deep Learning-Based Anomaly Detection from Distributed System Logs
复制标题

DOI:
10.1145/3422337.3447833
复制
发表时间:
2021-04
期刊:
Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
J. D. Herath;Ping Yang;Guanhua Yan
J. D. Herath;Ping Yang;Guanhua Yan
中科院分区:
其他
文献类型:
--
作者:
J. D. Herath;Ping Yang;Guanhua Yan

文献摘要

被引文献

相似文献

分布式系统日志记录了分布式系统执行过程中发生的状态和事件,为故障排除和诊断其操作问题提供了有价值的信息。由于这些系统的复杂性,最近有一些研究工作是使用深度学习模型从分布式系统日志中自动检测异常。由于这些异常检测模型也可用于检测分布式系统内的恶意活动,因此了解它们在对抗性环境中对规避操作的鲁棒性非常重要。尽管在自然语言处理和图像分类等领域存在针对深度学习模型的各种攻击,但它们不能直接应用于规避分布式系统日志的异常检测。在这项工作中,我们探索了分布式系统日志上基于深度学习的异常检测模型的对抗鲁棒性。我们提出了一种名为LAM(Log Anomaly Mask)的实时攻击方法,以在线方式以最小的修改来干扰流日志,以便攻击可以逃避最先进的深度学习模型的异常检测。为了克服搜索空间复杂性的挑战,LAM将扰动器建模为在部分可观察环境中操作的强化学习代理,以预测最佳扰动动作。我们已经评估了LAM在分布式系统的两个基于日志的异常检测系统上的有效性:DeepLog和基于AutoEncoder的异常检测系统。我们的实验结果表明,LAM显着降低这两个模型的真阳性率,同时实现攻击的不可感知性和实时响应。
Distributed system logs, which record states and events that occurred during the execution of a distributed system, provide valuable information for troubleshooting and diagnosis of its operational issues. Due to the complexity of such systems, there have been some recent research efforts on automating anomaly detection from distributed system logs using deep learning models. As these anomaly detection models can also be used to detect malicious activities inside distributed systems, it is important to understand their robustness against evasive manipulations in adversarial environments. Although there are various attacks against deep learning models in domains such as natural language processing and image classification, they cannot be applied directly to evade anomaly detection from distributed system logs. In this work, we explore the adversarial robustness of deep learning-based anomaly detection models on distributed system logs. We propose a real-time attack method called LAM (Log Anomaly Mask) to perturb streaming logs with minimal modifications in an online fashion so that the attacks can evade anomaly detection by even the state-of-the-art deep learning models. To overcome the search space complexity challenge, LAM models the perturber as a reinforcement learning agent that operates in a partially observable environment to predict the best perturbation action. We have evaluated the effectiveness of LAM on two log-based anomaly detection systems for distributed systems: DeepLog and an AutoEncoder-based anomaly detection system. Our experimental results show that LAM significantly reduces the true positive rate of these two models while achieving attack imperceptibility and real-time responsiveness.