Hide metadata

dc.date.accessioned2021-06-15T15:43:54Z
dc.date.available2021-06-15T15:43:54Z
dc.date.created2021-06-14T08:34:13Z
dc.date.issued2021
dc.identifier.citationClausen, Henry Grov, Gudmund Aspinall, David . CBAM: A Contextual Model for Network Anomaly Detection. Computers. 2021, 10(6)
dc.identifier.urihttp://hdl.handle.net/10852/86386
dc.description.abstractAnomaly-based intrusion detection methods aim to combat the increasing rate of zero-day attacks, however, their success is currently restricted to the detection of high-volume attacks using aggregated traffic features. Recent evaluations show that the current anomaly-based network intrusion detection methods fail to reliably detect remote access attacks. These are smaller in volume and often only stand out when compared to their surroundings. Currently, anomaly methods try to detect access attack events mainly as point anomalies and neglect the context they appear in. We present and examine a contextual bidirectional anomaly model (CBAM) based on deep LSTM-networks that is specifically designed to detect such attacks as contextual network anomalies. The model efficiently learns short-term sequential patterns in network flows as conditional event probabilities. Access attacks frequently break these patterns when exploiting vulnerabilities, and can thus be detected as contextual anomalies. We evaluated CBAM on an assembly of three datasets that provide both representative network access attacks, real-life traffic over a long timespan, and traffic from a real-world red-team attack. We contend that this assembly is closer to a potential deployment environment than current NIDS benchmark datasets. We show that, by building a deep model, we are able to reduce the false positive rate to 0.16% while effectively detecting six out of seven access attacks, which is significantly lower than the operational range of other methods. We further demonstrate that short-term flow structures remain stable over long periods of time, making the CBAM robust against concept drift.
dc.languageEN
dc.rightsAttribution 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.titleCBAM: A Contextual Model for Network Anomaly Detection
dc.typeJournal article
dc.creator.authorClausen, Henry
dc.creator.authorGrov, Gudmund
dc.creator.authorAspinall, David
cristin.unitcode185,15,5,75
cristin.unitnameDIS Digital infrastruktur og sikkerhet
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1
dc.identifier.cristin1915474
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.jtitle=Computers&rft.volume=10&rft.spage=&rft.date=2021
dc.identifier.jtitleComputers
dc.identifier.volume10
dc.identifier.issue6
dc.identifier.doihttps://doi.org/10.3390/computers10060079
dc.identifier.urnURN:NBN:no-89027
dc.type.documentTidsskriftartikkel
dc.type.peerreviewedPeer reviewed
dc.source.issn2073-431X
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/86386/2/computers-10-00079.pdf
dc.type.versionPublishedVersion
cristin.articleid79


Files in this item

Appears in the following Collection

Hide metadata

Attribution 4.0 International
This item's license is: Attribution 4.0 International