Deep learning for collective anomaly detection

被引:30
作者
Ahmed, Mohiuddin [1 ]
Pathan, Al-Sakib Khan [2 ]
机构
[1] Canberra Inst Technol, Dept ICT & Lib Studies, Reid, ACT 2601, Australia
[2] Southeast Univ, Dept Comp Sci & Engn, Dhaka 1213, Bangladesh
关键词
deep learning; collective anomaly; DoS attack; network; traffic analysis;
D O I
10.1504/IJCSE.2020.105220
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Deep learning has been performing well in a number of application domains. Inspired by its popularity in domains such as image processing, speech recognition, etc., in this paper we explore the effectiveness of deep learning and other supervised learning algorithms for collective anomaly detection. Recently, collective anomaly has become popular for denial of service (DoS) attack detection, however, all these approaches are unsupervised in nature and often have high false alarm rate due to being unsupervised. Therefore, to reduce the false alarm rates, we have experimented using the deep learning method which is supervised in nature. Our experimental results on UNSW-NB15 and KDD Cup 1999 datasets show that the deep learning implemented using H2O achieves approximate to 97% recall for collective anomaly detection. Deep learning outperforms a wide range of unsupervised techniques for collective anomaly detection. The key insight of this paper is to report the efficiency of deep learning for collective anomaly detection. To the best of our knowledge, this paper is the first one to address the collective anomaly detection problem using deep learning.
引用
收藏
页码:137 / 145
页数:9
相关论文
共 36 条
[1]   Trusted Autonomy and Cognitive Cyber Symbiosis: Open Challenges [J].
Abbass, Hussein A. ;
Petraki, Eleni ;
Merrick, Kathryn ;
Harvey, John ;
Barlow, Michael .
COGNITIVE COMPUTATION, 2016, 8 (03) :385-408
[2]  
Ahmed Mohiuddin, 2017, 2017 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM), P998, DOI 10.1145/3110025.3119402
[3]  
Ahmed M., 2015, ANN DATA SCI, V2, P111, DOI [DOI 10.1007/S40745-015-0035-Y, 10.1007/s40745-015-0035-y.]
[4]   Thwarting DoS Attacks: A Framework for Detection based on Collective Anomalies and Clustering [J].
Ahmed, Mohiuddin .
COMPUTER, 2017, 50 (09) :76-82
[5]   Network Traffic Pattern Analysis Using Improved Information Theoretic Co-clustering Based Collective Anomaly Detection [J].
Ahmed, Mohiuddin ;
Mahmood, Abdun Naser .
INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT II, 2015, 153 :204-219
[6]   A survey of network anomaly detection techniques [J].
Ahmed, Mohiuddin ;
Mahmood, Abdun Naser ;
Hu, Jiankun .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 60 :19-31
[7]  
Ahmed M, 2014, C IND ELECT APPL, P1141, DOI 10.1109/ICIEA.2014.6931337
[8]  
[Anonymous], EAI ENDORSED T SCALA
[9]  
[Anonymous], 1980, Identification of outliers, DOI [DOI 10.1007/978-94-015-3994-4, 10.1007/978-94-015-3994-4]
[10]  
[Anonymous], 2016, THESIS