Filtering DDoS Attacks from Unlabeled Network Traffic Data Using Online Deep Learning

12/12/2020
by   Wesley Joon-Wie Tann, et al.
0

DDoS attacks are simple, effective, and still pose a significant threat even after more than two decades. Given the recent success in machine learning, it is interesting to investigate how we can leverage deep learning to filter out application layer attack requests. There are challenges in adopting deep learning solutions due to the ever-changing profiles, the lack of labeled data, and constraints in the online setting. Offline unsupervised learning methods can sidestep these hurdles by learning an anomaly detector N from the normal-day traffic 𝒩. However, anomaly detection does not exploit information acquired during attacks, and their performance typically is not satisfactory. In this paper, we propose two frameworks that utilize both the historic 𝒩 and the mixture ℳ traffic obtained during attacks, consisting of unlabeled requests. We also introduce a machine learning optimization problem that aims to sift out the attacks using 𝒩 and ℳ. First, our proposed approach, inspired by statistical methods, extends an unsupervised anomaly detector N to solve the problem using estimated conditional probability distributions. We adopt transfer learning to apply N on 𝒩 and ℳ separately and efficiently, combining the results to obtain an online learner. Second, we formulate a specific loss function more suited for deep learning and use iterative training to solve it in the online setting. On publicly available datasets, our online learners achieve a 99.3% improvement on false-positive rates compared to the baseline detection methods. In the offline setting, our approaches are competitive with classifiers trained on labeled data.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/27/2021

Poisoning of Online Learning Filters: DDoS Attacks and Countermeasures

The recent advancements in machine learning have led to a wave of intere...
research
05/25/2023

Towards Total Online Unsupervised Anomaly Detection and Localization in Industrial Vision

Although existing image anomaly detection methods yield impressive resul...
research
05/16/2021

Understanding the Effect of Bias in Deep Anomaly Detection

Anomaly detection presents a unique challenge in machine learning, due t...
research
08/31/2023

Deep Semi-Supervised Anomaly Detection for Finding Fraud in the Futures Market

Modern financial electronic exchanges are an exciting and fast-paced mar...
research
08/15/2018

Anomaly Detection in Cyber Network Data Using a Cyber Language Approach

As the amount of cyber data continues to grow, cyber network defenders a...
research
10/04/2020

DNS Covert Channel Detection via Behavioral Analysis: a Machine Learning Approach

Detecting covert channels among legitimate traffic represents a severe c...
research
05/28/2020

Detection of Lying Electrical Vehicles in Charging Coordination Application Using Deep Learning

The simultaneous charging of many electric vehicles (EVs) stresses the d...

Please sign up or login with your details

Forgot password? Click here to reset