ASNM Datasets: A Collection of Network Attacks for Testing of Adversarial Classifiers and Intrusion Detectors

被引:9
|
作者
Homoliak, Ivan [1 ]
Malinka, Kamil [1 ]
Hanacek, Petr [1 ]
机构
[1] Brno Univ Technol, Fac Informat Technol, Ctr Excellence IT4Innovat, Brno 61200, Czech Republic
关键词
Feature extraction; Protocols; Network intrusion detection; Servers; Detectors; Dataset; network intrusion detection; adversarial classification; evasions; ASNM features; buffer overflow; non-payload-based obfuscations; tunneling obfuscations; SQUARE FEATURE-SELECTION; DETECTION SYSTEMS; DATA SET; OPTIMIZATION; CLASSIFICATION; ALGORITHMS; TAXONOMY; ENSEMBLE;
D O I
10.1109/ACCESS.2020.3001768
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present three datasets that have been built from network traffic traces using ASNM (Advanced Security Network Metrics) features, designed in our previous work. The first dataset was built using a state-of-the-art dataset CDX 2009 that was collected during a cyber defense exercise, while the remaining two datasets were collected by us in 2015 and 2018 using publicly available network services containing buffer overflow and other high severity vulnerabilities. These two datasets contain several adversarial obfuscation techniques that were applied onto malicious as well as legitimate traffic samples during "the execution" of their TCP network connections. Adversarial obfuscation techniques were used for evading machine learning-based network intrusion detection classifiers. We show that the performance of such classifiers can be improved when partially augmenting their training data by samples obtained from obfuscation techniques. In detail, we utilized tunneling obfuscation in HTTP(S) protocol and non-payload-based obfuscations modifying various properties of network traffic by, e.g., TCP segmentation, re-transmissions, corrupting and reordering of packets, etc. To the best of our knowledge, this is the first collection of network traffic data that contains adversarial techniques and is intended for non-payload-based network intrusion detection and adversarial classification. Provided datasets enable testing of the evasion resistance of arbitrary machine learning-based classifiers.
引用
收藏
页码:112427 / 112453
页数:27
相关论文
共 39 条
  • [1] XAI-driven Adversarial Attacks on Network Intrusion Detectors
    Okada, Satoshi
    Jmila, Houda
    Akashi, Kunio
    Mitsunaga, Takuho
    Sekiya, Yuji
    Takase, Hideki
    Blanc, Gregory
    Nakamura, Hiroshi
    PROCEEDINGS OF THE 2024 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2024, 2024, : 65 - 73
  • [2] Toward Transferable Adversarial Attacks Against Autoencoder-Based Network Intrusion Detectors
    Zhang, Yihang
    Wu, Yingwen
    Huang, Xiaolin
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (12) : 13863 - 13872
  • [3] Xai-driven black-box adversarial attacks on network intrusion detectors
    Okada, Satoshi
    Jmila, Houda
    Akashi, Kunio
    Mitsunaga, Takuho
    Sekiya, Yuji
    Takase, Hideki
    Blanc, Gregory
    Nakamura, Hiroshi
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (03)
  • [4] Enhancing the Sustainability of Deep-Learning-Based Network Intrusion Detection Classifiers against Adversarial Attacks
    Alotaibi, Afnan
    Rassam, Murad A.
    SUSTAINABILITY, 2023, 15 (12)
  • [5] Resampling Imbalanced Network Intrusion Datasets to Identify Rare Attacks
    Bagui, Sikha
    Mink, Dustin
    Bagui, Subhash
    Subramaniam, Sakthivel
    Wallace, Daniel
    FUTURE INTERNET, 2023, 15 (04)
  • [6] On Generating Network Traffic Datasets with Synthetic Attacks for Intrusion Detection
    Cordero, Carlos Garcia
    Vasilomanolakis, Emmanouil
    Wainakh, Aidmar
    Muhlhauser, Max
    Nadjm-Tehrani, Simin
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2021, 24 (02)
  • [7] Investigating the practicality of adversarial evasion attacks on network intrusion detection
    Merzouk, Mohamed Amine
    Cuppens, Frederic
    Boulahia-Cuppens, Nora
    Yaich, Reda
    ANNALS OF TELECOMMUNICATIONS, 2022, 77 (11-12) : 763 - 775
  • [8] Investigating the practicality of adversarial evasion attacks on network intrusion detection
    Mohamed Amine Merzouk
    Frédéric Cuppens
    Nora Boulahia-Cuppens
    Reda Yaich
    Annals of Telecommunications, 2022, 77 : 763 - 775
  • [9] Enhancing network intrusion detection classifiers using supervised adversarial training
    Yin, Chuanlong
    Zhu, Yuefei
    Liu, Shengli
    Fei, Jinlong
    Zhang, Hetong
    JOURNAL OF SUPERCOMPUTING, 2020, 76 (09): : 6690 - 6719
  • [10] Adversarial Attacks Against Network Intrusion Detection in IoT Systems
    Qiu, Han
    Dong, Tian
    Zhang, Tianwei
    Lu, Jialiang
    Memmi, Gerard
    Qiu, Meikang
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (13) : 10327 - 10335