Attackers are now using sophisticated techniques, like polymorphism, to change the attack pattern for each new attack. Thus, the detection of novel attacks has become the biggest challenge for cyber experts and researchers. Recently, anomaly and hybrid approaches are used for the detection of network attacks. Detecting novel attacks, on the other hand, is a key enabler for a wide range of IoT applications. Novel attacks can easily evade existing signature-based detection methods and are extremely difficult to detect, even going undetected for years. Existing machine learning models have also failed to detect the attack and have a high rate of false positives. In this paper, a rule-based deep neural network technique has been proposed as a framework for addressing the problem of detecting novel attacks. The designed framework significantly improves respective benchmark results, including the CICIDS 2017 dataset. The experimental results show that the proposed model keeps a good balance between attack detection, untruthful positive rates, and untruthful negative rates. For novel attacks, the model has an accuracy of more than 99%. During the automatic interaction between network-devices (IoT), security and privacy are the primary obstacles. Our proposed method can handle these obstacles efficiently and finally identify, and classify the different levels of threats.
翻译:攻击者正利用诸如多态性等复杂技术,为每次新攻击改变攻击模式。因此,检测新攻击已成为网络安全专家和研究者面临的最大挑战。近年来,异常检测和混合方法被用于网络攻击检测,而检测新攻击则是众多物联网应用的关键支撑。新攻击能轻易绕过现有的基于签名的检测方法,极难被发现,甚至可能潜藏数年而不被察觉。现有的机器学习模型也未能有效检测此类攻击,且误报率较高。本文提出一种基于规则的深度神经网络技术框架,用于解决新攻击检测问题。该设计框架显著提升了包括CICIDS 2017数据集在内的相关基准测试结果。实验表明,该模型在攻击检测率、假阳性率与假阴性率之间保持了良好平衡。针对新攻击,模型准确率超过99%。在物联网设备自动交互过程中,安全与隐私是主要障碍。本文提出的方法能有效应对这些障碍,最终实现不同威胁等级的识别与分类。