Return
Early Attack Identification in the Wild
DOI:10.1109/TON.2026.3677135.png)
Abstract
En 中文
While characterizing network connections in their early stage is vital for providing timely responses against network threats, existing methods become less attractive due to the requirement of complete connection information (thus unable to make timely identification) or packet payload inspection (therefore limited to unencrypted packets under no privacy regulation). To this end, this paper takes an approach of packet stream analysis referencing statistical information of packet sequences, requiring neither packet inspection nor complete connection information. To enable practical packet stream analysis, there exist several challenges, such as out-of-order packet sequences introduced by network dynamics and class imbalance with a tiny fraction of attack connections. To overcome these challenges, we design two deep sequence models: 1) a bidirectional recurrent structure designed for greater resilience to out-of-order packet streams; and 2) a pre-training-enabled sequence-to-sequence structure designed for creating consistent representations from unbalanced class distributions using self-supervised learning. We evaluate the presented deep sequence models using real and synthetic network data collections for extensive experimentation. The experimental results support the feasibility of the proposed models outperforming baseline deep learning models, yielding up to 94.8% (F1 score) only with the first five packets ( k =5) from the Internet traffic collection containing a substantial fraction of network flows experiencing out-of-order delivery.
Keywords:
Payloads
Inspection
Deep learning
Analytical models
Out of order
Data models
Monitoring
Data collection
Anomaly detection
Privacy
Packet stream
early characterization
out-of-order packets
class imbalance
deep sequence
neural networks
Journal
I
IF:
0
Papers:
543
Citations:
0

