三叉戟
异常检测
可扩展性
计算机科学
班级(哲学)
聚类分析
入侵检测系统
仿形(计算机编程)
数据挖掘
离群值
加密
计算机安全
分布式计算
人工智能
数据库
操作系统
考古
历史
作者
Ziming Zhao,Zhaoxuan Li,Zhuoxue Song,Wenhao Li,Fan Zhang
标识
DOI:10.1145/3589334.3645407
摘要
To detect unknown attack traffic, anomaly-based network intrusion detection systems (NIDSs) are widely used in Internet infrastructure. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained emerging attack detection and (ii) incremental updates/adaptations. To tackle these problems, we propose to decouple the need for model capabilities by transforming known/new class identification issues into multiple independent one-class learning tasks. Based on the above core ideas, we develop Trident, a universal framework for fine-grained unknown encrypted traffic detection. It consists of three main modules, i.e., tSieve, tScissors, and tMagnifier are used for profiling traffic, determining outlier thresholds, and clustering respectively, each of which supports custom configuration. Using four popular datasets of network traces, we show that Trident significantly outperforms 16 state-of-the-art (SOTA) methods. Furthermore, a series of experiments (concept drift, overhead/parameter evaluation) demonstrate the stability, scalability, and practicality of Trident.
科研通智能强力驱动
Strongly Powered by AbleSci AI