Machine Learning (ML) can be incredibly valuable to automate anomaly detection and cyber-attack classification, improving the way that Network Intrusion Detection (NID) is performed. However, despite the benefits of ML models, they are highly susceptible to adversarial cyber-attack examples specifically crafted to exploit them. A wide range of adversarial attacks have been created and researchers have worked on various defense strategies to safeguard ML models, but most were not intended for the specific constraints of a communication network and its communication protocols, so they may lead to unrealistic examples in the NID domain. This Systematization of Knowledge (SoK) consolidates and summarizes the state-of-the-art adversarial learning approaches that can generate realistic examples and could be used in real ML development and deployment scenarios with real network traffic flows. This SoK also describes the open challenges regarding the use of adversarial ML in the NID domain, defines the fundamental properties that are required for an adversarial example to be realistic, and provides guidelines for researchers to ensure that their future experiments are adequate for a real communication network.
翻译:机器学习(ML)在自动化异常检测与网络攻击分类方面具有极高价值,可显著提升网络入侵检测(NID)的实施方式。然而,尽管ML模型拥有诸多优势,它们极易受到专门为利用其漏洞而精心设计的对抗性网络攻击样本的影响。目前已有大量对抗攻击被创建,研究人员也研究出了多种防御策略来保护ML模型,但大多数方法并未考虑通信网络及其通信协议的具体约束条件,因此在NID领域可能产生不现实的样本。本知识系统化(SoK)梳理并总结了现有最先进的对抗学习方法,这些方法能够生成现实样本,并可在真实网络流量流的ML开发与部署场景中使用。此外,本文还描述了在NID领域中应用对抗性ML所面临的开放挑战,定义了对抗样本需具备现实性的基本特性,并为研究人员提供了相关指南,以确保其未来实验适用于真实通信网络。