Inicio  /  Applied Sciences  /  Vol: 12 Par: 3 (2022)  /  Artículo
ARTÍCULO
TITULO

Combining Unsupervised Approaches for Near Real-Time Network Traffic Anomaly Detection

Francesco Carrera    
Vincenzo Dentamaro    
Stefano Galantucci    
Andrea Iannacone    
Donato Impedovo and Giuseppe Pirlo    

Resumen

The 0-day attack is a cyber-attack based on vulnerabilities that have not yet been published. The detection of anomalous traffic generated by such attacks is vital, as it can represent a critical problem, both in a technical and economic sense, for a smart enterprise as for any system largely dependent on technology. To predict this kind of attack, one solution can be to use unsupervised machine learning approaches, as they guarantee the detection of anomalies regardless of their prior knowledge. It is also essential to identify the anomalous and unknown behaviors that occur within a network in near real-time. Three different approaches have been proposed and benchmarked in exactly the same condition: Deep Autoencoding with GMM and Isolation Forest, Deep Autoencoder with Isolation Forest, and Memory Augmented Deep Autoencoder with Isolation Forest. These approaches are thus the result of combining different unsupervised algorithms. The results show that the addition of the Isolation Forest improves the accuracy values and increases the inference time, although this increase does not represent a relevant problematic factor. This paper also explains the features that the various models consider most important for classifying an event as an attack using the explainable artificial intelligence methodology called Shapley Additive Explanations (SHAP). Experiments were conducted on KDD99, NSL-KDD, and CIC-IDS2017 datasets.

 Artículos similares

       
 
Theiab Alzahrani, Baidaa Al-Bander and Waleed Al-Nuaimy    
Makeup can disguise facial features, which results in degradation in the performance of many facial-related analysis systems, including face recognition, facial landmark characterisation, aesthetic quantification and automated age estimation methods. Thu... ver más
Revista: AI

 
Louis Béthune, Yacouba Kaloga, Pierre Borgnat, Aurélien Garivier and Amaury Habrard    
We propose a novel algorithm for unsupervised graph representation learning with attributed graphs. It combines three advantages addressing some current limitations of the literature: (i) The model is inductive: it can embed new graphs without re-trainin... ver más
Revista: Algorithms

 
Huajun Song, Jie Song and Peng Ren    
The existing oil spill detection methods mainly rely on physical sensors or numerical models cannot locate the spill position accurately and in time. To solve this problem, combining with underwater image processing technology, an unsupervised detection ... ver más

 
Menglin Li, Xueqiang Gu, Chengyi Zeng and Yuan Feng    
Reinforcement learning, as a branch of machine learning, has been gradually applied in the control field. However, in the practical application of the algorithm, the hyperparametric approach to network settings for deep reinforcement learning still follo... ver más
Revista: Algorithms

 
Krzysztof Malczewski    
One of the most challenging aspects of medical modalities such as Computed Tomography (CT) as well hybrid techniques such as CT/PET (Computed Tomography/Positron emission tomography) and PET/MRI is finding a balance between examination time, radiation do... ver más
Revista: Algorithms