Back to Search Start Over

Adaptive Clustering-based Malicious Traffic Classification at the Network Edge

Authors :
Alec F. Diallo
Paul Patras
Source :
INFOCOM, Diallo, A F & Patras, P 2021, Adaptive Clustering-based Malicious Traffic Classification at the Network Edge . in IEEE INFOCOM 2021-IEEE Conference on Computer Communications . Institute of Electrical and Electronics Engineers (IEEE), 2021 IEEE International Conference on Computer Communications, Virtual Conference, 10/05/21 . https://doi.org/10.1109/INFOCOM42981.2021.9488690
Publication Year :
2021
Publisher :
IEEE, 2021.

Abstract

The rapid uptake of digital services and Internet of Things (IoT) technology gives rise to unprecedented numbers and diversification of cyber attacks, with which commonly-used rule-based Network Intrusion Detection Systems (NIDSs) are struggling to cope. Therefore, Artificial Intelligence (AI) is being exploited as second line of defense, since this methodology helps in extracting non-obvious patterns from network traffic and subsequently in detecting more confidently new types of threats. Cybersecurity is however an arms race and intelligent solutions face renewed challenges as attacks evolve while network traffic volumes surge. In this paper, we propose Adaptive Clustering-based Intrusion Detection (ACID), a novel approach to malicious traffic classification and a valid candidate for deployment at the network edge. ACID addresses the critical challenge of sensitivity to subtle changes in traffic features, which routinely leads to misclassification. We circumvent this problem by relying on low-dimensional embeddings learned with a lightweight neural model comprising multiple kernel networks that we introduce, which optimally separates samples of different classes. We empirically evaluate our approach with both synthetic and three intrusion detection datasets spanning 20 years, and demonstrate ACID consistently attains 100% accuracy and F1-score, and 0% false alarm rate, thereby significantly outperforming state-of-the-art clustering methods and NIDSs.

Details

Database :
OpenAIRE
Journal :
IEEE INFOCOM 2021 - IEEE Conference on Computer Communications
Accession number :
edsair.doi.dedup.....bced54c7904b50bd50c905a54235a633
Full Text :
https://doi.org/10.1109/infocom42981.2021.9488690