FlowSpectrum: a concrete characterization scheme of network traffic behavior for anomaly detection

被引:6
作者
Yang, Luming [1 ]
Fu, Shaojing [1 ]
Zhang, Xuyun [2 ]
Guo, Shize [3 ]
Wang, Yongjun [1 ]
Yang, Chi [4 ]
机构
[1] Natl Univ Def Technol, Changsha, Peoples R China
[2] Natl Res Ctr Informat Technol Secur, Beijing, Peoples R China
[3] Macquarie Univ, Sydney, NSW, Australia
[4] Huazhong Univ Sci & Technol, Beijing, Peoples R China
来源
WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS | 2022年 / 25卷 / 05期
基金
澳大利亚研究理事会;
关键词
FlowSpectrum; Network flow analysis; Anomaly detection; Characterization; INTRUSION DETECTION METHOD; CLASSIFICATION; VISUALIZATION;
D O I
10.1007/s11280-022-01057-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the 5G rolls out around the world, many edge applications will be deployed by app vendors and accessed by massive end-users. Efficient detection of malicious network behavior is paid more and more attention. The current traffic detection work is still stuck on the analysis of high-dimensional data. It will restrict the improvement of threat monitoring and network governance when facing massive network flows. Characterization of network flows within simple domains is required to simplify the process of network analysis. Traffic characterization is a key task that allows service providers to detect and intercept anomalous traffic, such that high QoS (Quality of Service) and service availability are maintained and spread of malicious content is prevented. Unfortunately, there is still a lack of research on the concrete characterization of network data. Analogous to spectrum, in this paper, we proposed the concept of FlowSpectrum for the first time in order to represent the network flow, concretely. In the FlowSpectrum, network flow is represented as a spectral line rather than the raw data or a feature vector of the network flow. All flows are able to be mapped as spectral lines, and traffic identification is achieved by analyzing the positions of spectral lines. FlowSpectrum can significantly reduce the complexity of network traffic behavior analysis while enhancing the interpretability of detection and facilitating cyberspace behavior management. We designed a neural network structure based on semi-supervised AutoEncoder for decomposition and dimensionality reduction of network flows in FlowSpectrum. The characterization capability of FlowSpectrum is proved by thorough experiments. Moreover, we realized the correspondence between network behaviors and intervals of spectral lines, preliminarily. Generally speaking, FlowSpectrum can provide new ideas for the field of network traffic analysis.
引用
收藏
页码:2139 / 2161
页数:23
相关论文
共 41 条
  • [41] A 3D Approach for the Visualization of Network Intrusion Detection Data
    Zong, Wei
    Chow, Yang-Wai
    Susilo, Willy
    [J]. 2018 INTERNATIONAL CONFERENCE ON CYBERWORLDS (CW), 2018, : 308 - 315