Importance Analysis of Micro-Flow Independent Features for Detecting Distributed Network Attacks

被引:0
作者
Kopmann, Samuel [1 ]
Zitterbart, Martina [2 ]
机构
[1] Institute of Telematics, Karlsruhe Institute of Technology, Karlsruhe
[2] Karlsruhe Institute of Technology, KASTEL Security Research Labs, Karlsruhe
来源
IEEE Transactions on Network and Service Management | 2024年 / 21卷 / 06期
关键词
machine learning; Network intrusion detection; traffic aggregation; traffic monitoring;
D O I
10.1109/TNSM.2024.3460082
中图分类号
学科分类号
摘要
Network infrastructures are critical and, therefore, subject to harmful attacks against their operation and the availability of their provided services. Detecting such attacks, especially in high-performance networks, is challenging considering the detection rate, reaction time, and scalability. Attack detection becomes even more demanding concerning networks of the future facing increasing data rates and flow counts. We thoroughly evaluate eMinD, an approach that scales well to high data rates and large amounts of data flows. eMinD investigates aggregated traffic data, i.e., it is not based on micro-flows and their inherent scalability problems. We evaluate eMinD with real-world traffic data, compare it to related work, and show that eMinD outperforms micro-flow-based approaches regarding the reaction time, scalability, and the detection performance. We reduce required state space by 99.97%. The average reaction time is reduced by 90%, while the detection performance is even increased, although highly aggregating arriving traffic. We further show the importance of micro-flow-overarching traffic features, e.g., IP address and port distributions, for detecting distributed network attacks, i.e., DDoS attacks and port scans. © 2004-2012 IEEE.
引用
收藏
页码:5947 / 5957
页数:10
相关论文
共 6 条
  • [1] MIDA: Micro-flow Independent Detection of DDoS Attacks with CNNs
    Kopmann, Samuel
    Heseding, Hauke
    Zitterbart, Martina
    ADVANCES IN SERVICE-ORIENTED AND CLOUD COMPUTING, ESOCC 2022, 2022, 1617 : 32 - 43
  • [2] Sensitivity and Uncertainty Analysis of Micro-Flow Imaging for Sub-Visible Particle Measurements Using Artificial Neural Network
    Sadegh Poozesh
    Flavio Cannavò
    Prakash Manikwar
    Pharmaceutical Research, 2023, 40 : 721 - 733
  • [3] Sensitivity and Uncertainty Analysis of Micro-Flow Imaging for Sub-Visible Particle Measurements Using Artificial Neural Network
    Poozesh, Sadegh
    Cannavo, Flavio
    Manikwar, Prakash
    PHARMACEUTICAL RESEARCH, 2023, 40 (03) : 721 - 733
  • [4] Analysis of NetFlow Features' Importance in Malicious Network Traffic Detection
    Campazas-Vega, Adrian
    Samuel Crespo-Martinez, Ignacio
    Manuel Guerrero-Higueras, Angel
    Alvarez-Aparicio, Claudia
    Matellan, Vicente
    14TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE IN SECURITY FOR INFORMATION SYSTEMS AND 12TH INTERNATIONAL CONFERENCE ON EUROPEAN TRANSNATIONAL EDUCATIONAL (CISIS 2021 AND ICEUTE 2021), 2022, 1400 : 52 - 61
  • [5] A distributed approach to network anomaly detection based on independent component analysis
    Palmieri, Francesco
    Fiore, Ugo
    Castiglione, Aniello
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2014, 26 (05) : 1113 - 1129
  • [6] Applying domain-specific knowledge to construct features for detecting distributed denial-of-service attacks on the GOOSE and MMS protocols
    Lahza, Hassan
    Radke, Kenneth
    Foo, Ernest
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2018, 20 : 48 - 67