Towards Evaluation of NIDSs in Adversarial Setting

Towards Evaluation of NIDSs in Adversarial Setting
复制标题

DOI:
10.1145/3359992.3366642
复制
发表时间:
2019-12
期刊:
Proceedings of the 3rd ACM CoNEXT Workshop on Big DAta, Machine Learning and Artificial Intelligence for Data Communication Networks
影响因子:
--
通讯作者:
Mohammad J. Hashemi;Greg Cusack;Eric Keller
Mohammad J. Hashemi;Greg Cusack;Eric Keller
中科院分区:
其他
文献类型:
--
作者:
Mohammad J. Hashemi;Greg Cusack;Eric Keller

文献摘要

被引文献

相似文献

基于特征的网络入侵检测系统(NIDS)传统上用于检测恶意流量,但它们无法检测新的威胁。因此,基于神经网络的基于异常的NIDS由于其寻找新攻击的能力而开始受到关注。然而,已经表明,神经网络在其他领域容易受到对抗性示例攻击。但是,以前提出的基于异常的NIDS还没有在这样的对抗环境中进行评估。在本文中,我们展示了如何评估一个基于异常的NIDS训练网络流量在面对敌对的输入。我们展示了如何在高度约束的网络域中制作对抗性输入,并在对抗性设置中评估了3个最近提出的NIDS。
Signature-based Network Intrusion Detection Systems (NIDSs) have traditionally been used to detect malicious traffic, but they are incapable of detecting new threats. As a result, anomaly-based NIDSs, built on neural networks, are beginning to receive attention due to their ability to seek out new attacks. However, it has been shown that neural networks are vulnerable to adversarial example attacks in other domains. But, previously proposed anomaly-based NIDSs have not been evaluated in such adversarial settings. In this paper, we show how to evaluate an anomaly-based NIDS trained on network traffic in the face of adversarial inputs. We show how to craft adversarial inputs in the highly constrained network domain, and we evaluate 3 recently proposed NIDSs in an adversarial setting.