ASNM Datasets: A Collection of Network Attacks for Testing of Adversarial Classifiers and Intrusion Detectors

被引:9
|
作者
Homoliak, Ivan [1 ]
Malinka, Kamil [1 ]
Hanacek, Petr [1 ]
机构
[1] Brno Univ Technol, Fac Informat Technol, Ctr Excellence IT4Innovat, Brno 61200, Czech Republic
关键词
Feature extraction; Protocols; Network intrusion detection; Servers; Detectors; Dataset; network intrusion detection; adversarial classification; evasions; ASNM features; buffer overflow; non-payload-based obfuscations; tunneling obfuscations; SQUARE FEATURE-SELECTION; DETECTION SYSTEMS; DATA SET; OPTIMIZATION; CLASSIFICATION; ALGORITHMS; TAXONOMY; ENSEMBLE;
D O I
10.1109/ACCESS.2020.3001768
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present three datasets that have been built from network traffic traces using ASNM (Advanced Security Network Metrics) features, designed in our previous work. The first dataset was built using a state-of-the-art dataset CDX 2009 that was collected during a cyber defense exercise, while the remaining two datasets were collected by us in 2015 and 2018 using publicly available network services containing buffer overflow and other high severity vulnerabilities. These two datasets contain several adversarial obfuscation techniques that were applied onto malicious as well as legitimate traffic samples during "the execution" of their TCP network connections. Adversarial obfuscation techniques were used for evading machine learning-based network intrusion detection classifiers. We show that the performance of such classifiers can be improved when partially augmenting their training data by samples obtained from obfuscation techniques. In detail, we utilized tunneling obfuscation in HTTP(S) protocol and non-payload-based obfuscations modifying various properties of network traffic by, e.g., TCP segmentation, re-transmissions, corrupting and reordering of packets, etc. To the best of our knowledge, this is the first collection of network traffic data that contains adversarial techniques and is intended for non-payload-based network intrusion detection and adversarial classification. Provided datasets enable testing of the evasion resistance of arbitrary machine learning-based classifiers.
引用
收藏
页码:112427 / 112453
页数:27
相关论文
共 39 条
  • [31] Adv-Bot: Realistic adversarial botnet attacks against network intrusion detection systems
    Debicha, Islam
    Cochez, Benjamin
    Kenaza, Tayeb
    Debatty, Thibault
    Dricot, Jean -Michel
    Mees, Wim
    COMPUTERS & SECURITY, 2023, 129
  • [32] Testing Convolutional Neural Network using Adversarial Attacks on Potential Critical Pixels
    Lin, Bo-Ching
    Hsu, Hwai-Jung
    Huang, Shih-Kun
    2020 IEEE 44TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2020), 2020, : 1743 - 1748
  • [33] Adversarial Attacks Against Deep Learning-Based Network Intrusion Detection Systems and Defense Mechanisms
    Zhang, Chaoyun
    Costa-Perez, Xavier
    Patras, Paul
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1294 - 1311
  • [34] Towards realistic problem-space adversarial attacks against machine learning in network intrusion detection
    Catillo, Marta
    Pecchia, Antonio
    Repola, Antonio
    Villano, Umberto
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [35] TAD: Transfer learning-based multi-adversarial detection of evasion attacks against network intrusion detection systems
    Debicha, Islam
    Bauwens, Richard
    Debatty, Thibault
    Dricot, Jean -Michel
    Kenaza, Tayeb
    Mees, Wim
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 138 : 185 - 197
  • [36] Def-IDS: An Ensemble Defense Mechanism Against Adversarial Attacks for Deep Learning-based Network Intrusion Detection
    Wang, Jianyu
    Pan, Jianli
    AlQerm, Ismail
    Liu, Yuanni
    30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [37] A Robust Network Intrusion Detection System Using Random Forest Based Random Subspace Ensemble to Defend Against Adversarial Attacks
    Nathaniel, Dhinakaran
    Soosai, Anto
    ADVANCES IN ELECTRICAL AND COMPUTER ENGINEERING, 2023, 23 (04) : 81 - 88
  • [38] Development of a Machine-Learning Intrusion Detection System and Testing of Its Performance Using a Generative Adversarial Network
    Mari, Andrei-Grigore
    Zinca, Daniel
    Dobrota, Virgil
    SENSORS, 2023, 23 (03)
  • [39] Multi-view consistent generative adversarial network for enhancing intrusion detection with prevention systems in mobile ad hoc networks against security attacks
    Rajkumar, M.
    Karthika, J.
    Abinayaa, S. S.
    COMPUTERS & SECURITY, 2025, 150