Exquisite Feature Selection for Machine Learning Powered Probing Attack Detection

Exquisite Feature Selection for Machine Learning Powered Probing Attack Detection
复制标题

DOI:
10.1109/icc45041.2023.10278886
复制
发表时间:
2023-05
期刊:
ICC 2023 - IEEE International Conference on Communications
影响因子:
--
通讯作者:
Hamidah Alanazi;Shengping Bi;Tao Wang;Tao Hou
Hamidah Alanazi;Shengping Bi;Tao Wang;Tao Hou
中科院分区:
其他
文献类型:
--
作者:
Hamidah Alanazi;Shengping Bi;Tao Wang;Tao Hou

文献摘要

被引文献

相似文献

最近的研究对网络攻击进行了深入的研究。然而,探测攻击似乎没有像其他攻击那样受到那么多的关注,因为它们不会明确地影响网络操作。但是,探测式攻击可以监控网络行为,提取web敏感信息,收集目标网络的拓扑信息,为其他攻击打开了方便之门。了解网络探测攻击的流量模式,防止攻击者进行可疑的探测活动是至关重要的。在这项工作中,我们提出了一种新的用户选择工具来构建可以表征探测攻击的最佳特征集。它由三个模块组成:1)特征相关分析器,去除高度相关的特征,提高训练效率;2)粗粒度特征选择,选择能够描述探测攻击流量模式的关键特征;3)细粒度特征细化,了解多个数据包之间的时空相关性,进一步提高检测率。此外,我们提出了一种快速混合训练架构,允许同时训练特征选择和攻击检测,以提高整体训练效率。在实验中,我们建立了一个真实的网络测试平台来验证我们的设计。结果表明,采用所提出的细粒度特征选择工具,检测模型的检测率高达99.74%。
Network attacks have been intensively studied by recent research. Probing attacks, however, seem not receiving as much attention as others, because they do not explicitly impact the network operations. Nevertheless, probing attacks may monitor network behaviors, extract web-sensitive information, and gather topology information of a target network, which opens a door for other attacks. It is critically important to understand the traffic patterns of network probing attacks and prevent suspicious probing activities from attackers. In this work, we present a novel user selection tool to build the optimal feature set that can characterize probing attacks. It consists of three modules: 1) feature correlation analyzer to remove highly correlated features for training efficiency; 2) coarse-grain feature selection to select key features that can describe the traffic patterns of probing attacks; 3) fine-grain feature refinement to understand temporal/spatial correlations among multiple packets to further improve the detection rate. In addition, we propose a fast hybrid training architecture that allows simultaneous training for both feature selection and attack detection to improve the overall training efficiency. In the experiment, we build a real-world network testbed to validate our design. The results show that the detection model can achieve a detection rate of up to 99.74% with the proposed fine-grain feature selection tool.