FlowSpectrum: a concrete characterization scheme of network traffic behavior for anomaly detection

被引:6
作者
Yang, Luming [1 ]
Fu, Shaojing [1 ]
Zhang, Xuyun [2 ]
Guo, Shize [3 ]
Wang, Yongjun [1 ]
Yang, Chi [4 ]
机构
[1] Natl Univ Def Technol, Changsha, Peoples R China
[2] Natl Res Ctr Informat Technol Secur, Beijing, Peoples R China
[3] Macquarie Univ, Sydney, NSW, Australia
[4] Huazhong Univ Sci & Technol, Beijing, Peoples R China
来源
WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS | 2022年 / 25卷 / 05期
基金
澳大利亚研究理事会;
关键词
FlowSpectrum; Network flow analysis; Anomaly detection; Characterization; INTRUSION DETECTION METHOD; CLASSIFICATION; VISUALIZATION;
D O I
10.1007/s11280-022-01057-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the 5G rolls out around the world, many edge applications will be deployed by app vendors and accessed by massive end-users. Efficient detection of malicious network behavior is paid more and more attention. The current traffic detection work is still stuck on the analysis of high-dimensional data. It will restrict the improvement of threat monitoring and network governance when facing massive network flows. Characterization of network flows within simple domains is required to simplify the process of network analysis. Traffic characterization is a key task that allows service providers to detect and intercept anomalous traffic, such that high QoS (Quality of Service) and service availability are maintained and spread of malicious content is prevented. Unfortunately, there is still a lack of research on the concrete characterization of network data. Analogous to spectrum, in this paper, we proposed the concept of FlowSpectrum for the first time in order to represent the network flow, concretely. In the FlowSpectrum, network flow is represented as a spectral line rather than the raw data or a feature vector of the network flow. All flows are able to be mapped as spectral lines, and traffic identification is achieved by analyzing the positions of spectral lines. FlowSpectrum can significantly reduce the complexity of network traffic behavior analysis while enhancing the interpretability of detection and facilitating cyberspace behavior management. We designed a neural network structure based on semi-supervised AutoEncoder for decomposition and dimensionality reduction of network flows in FlowSpectrum. The characterization capability of FlowSpectrum is proved by thorough experiments. Moreover, we realized the correspondence between network behaviors and intervals of spectral lines, preliminarily. Generally speaking, FlowSpectrum can provide new ideas for the field of network traffic analysis.
引用
收藏
页码:2139 / 2161
页数:23
相关论文
共 41 条
  • [1] Abadi M, 2016, ACM SIGPLAN NOTICES, V51, P1, DOI [10.1145/2951913.2976746, 10.1145/3022670.2976746]
  • [2] [Anonymous], 2012, Int. J. Eng. Innov. Technol. (IJEIT).
  • [3] Bouzida Y., 2004, EFFICIENT INTRUSION
  • [4] Chang Liu, 2019, IEEE INFOCOM 2019 - IEEE Conference on Computer Communications, P1171, DOI 10.1109/INFOCOM.2019.8737507
  • [5] Chen Y., 2021, KNOWL-BASED SYST
  • [6] Chen Yang., 2021, 2021 IEEE 18th Annual Consumer Communications Networking Conference (CCNC), P1
  • [7] An Adaptive Archive-Based Evolutionary Framework for Many-Task Optimization
    Chen, Yongliang
    Zhong, Jinghui
    Feng, Liang
    Zhang, Jun
    [J]. IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2020, 4 (03): : 369 - 384
  • [8] Chen ZT, 2017, IEEE INT CONF BIG DA, P1271, DOI 10.1109/BigData.2017.8258054
  • [9] Neural visualization of network traffic data for intrusion detection
    Corchado, Emilio
    Herrero, Alvaro
    [J]. APPLIED SOFT COMPUTING, 2011, 11 (02) : 2042 - 2056
  • [10] Draper-Gil Gerard, 2016, ICISSP 2016. 2nd International Conference on Information Systems Security and Privacy. Proceedings, P407