Return
CNN and RNN based payload classification methods for attack detection
DOI:10.1016/j.knosys.2018.08.036.png)
Abstract
En 中文
In recent years, machine learning has been widely applied to problems in detecting network attacks, particularly novel attacks. However, traditional machine learning methods depend heavily on feature engineering, and extracting features is often time-consuming and complex. Thus, it is impractical to detect attacks with traditional machine learning methods in real-time applications. To discover network attacks efficiently, we propose an end-to-end detection approach. We implement deep learning models to analyze payloads and propose a convolutional neural network-based payload classification approach (PL-CNN) and a recurrent neural network-based payload classification approach (PL-RNN) for use in attack detection. Our two approaches learn feature representations from original payloads without feature engineering and support end-to-end detection. These approaches achieve accuracies of 99.36% and 99.98% when applied to the DARPA1998 dataset, respectively; these accuracies are comparable to or better than those of state-of-the-art methods. In addition, our methods are efficient and practical. (C) 2018 Elsevier B.V. All rights reserved.
Keywords:
Payload
Deep learning
End-to-end
Attack detection
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
K
IF:
7.6
Papers:
1.3W
Citations:
4.5W
Organization
No organization information available
Cited Papers
A Hybrid Spectral Clustering and Deep Neural Network Ensemble Algorithm for Intrusion Detection in Sensor Networks
SENSORS
IF3.5
Photochemical and pharmacological aspects of nitric oxide release from some nitrosyl ruthenium complexes entrapped in sol–gel and silicone matrices
Polyhedron
IF0

