paper-with-me

홈 › Papers

Feature Extraction for Novelty Detection in Network Traffic

2020-06-30 · Kun Yang, Samory Kpotufe, Nick Feamster

Data representation plays a critical role in the performance of novelty detection (or ``anomaly detection'') methods in machine learning. The data representation of network traffic often determines the effectiveness of these models as much as the model itself. The wide range of novel events that network operators need to detect (e.g., attacks, malware, new applications, changes in traffic demands) introduces the possibility for a broad range of possible models and data representations. In each scenario, practitioners must spend significant effort extracting and engineering features that are most predictive for that situation or application. While anomaly detection is well-studied in computer networking, much existing work develops specific models that presume a particular representation -- often IPFIX/NetFlow. Yet, other representations may result in higher model accuracy, and the rise of programmable networks now makes it more practical to explore a broader range of representations. To facilitate such exploration, we develop a systematic framework, open-source toolkit, and public Python library that makes it both possible and easy to extract and generate features from network traffic and perform and end-to-end evaluation of these representations across most prevalent modern novelty detection models. We first develop and publicly release an open-source tool, an accompanying Python library (NetML), and end-to-end pipeline for novelty detection in network traffic. Second, we apply this tool to five different novelty detection problems in networking, across a range of scenarios from attack detection to novel device detection. Our findings general insights and guidelines concerning which features appear to be more appropriate for particular situations.

📄 PDF Abstract BibTeX arXiv:2006.16993

Code (0)

등록된 구현이 없습니다.

Tasks

Anomaly DetectionBIG-bench Machine LearningMalware DetectionNovelty Detection

Similar Papers 제목 키워드 기반

Novelty Detection in Network Traffic: Using Survival Analysis for Feature Identification

2023-01-16 · Taylor Bradley, Elie Alhajjar, Nathaniel Bastian

Intrusion Detection Systems are an important component of many organizations' cyber defense and resiliency strategies. However, one downside of these systems is their reliance on known attack signatures for detection of …

Intrusion DetectionNovelty DetectionSurvival Analysis

An Adaptable Deep Learning-Based Intrusion Detection System to Zero-Day Attacks

2021-08-20 · Mahdi Soltani, Behzad Ousat, Mahdi Jafari Siavoshani, Amir Hossein Jahangir

The intrusion detection system (IDS) is an essential element of security monitoring in computer networks. An IDS distinguishes the malicious traffic from the benign one and determines the attack types targeting the asset…

ClusteringIntrusion DetectionOpen Set Learning

Novelty-based Generalization Evaluation for Traffic Light Detection

2022-01-03 · Arvind Kumar Shekar, Laureen Lake, Liang Gou, Liu Ren

The advent of Convolutional Neural Networks (CNNs) has led to their application in several domains. One noteworthy application is the perception system for autonomous driving that relies on the predictions from CNNs. Pra…

Autonomous DrivingRepresentation Learning

IntrusionX: A Hybrid Convolutional-LSTM Deep Learning Framework with Squirrel Search Optimization for Network Intrusion Detection

2025-10-01 · Ahsan Farabi, Muhaiminul Rashid Shad, Israt Khandaker arxiv

Intrusion Detection Systems (IDS) face persistent challenges due to evolving cyberattacks, high-dimensional traffic data, and severe class imbalance in benchmark datasets such as NSL-KDD. To address these issues, we prop…

Network Intrusion DetectionComputational EfficiencyBinary Classification

CND-IDS: Continual Novelty Detection for Intrusion Detection Systems

2025-02-19 · Sean Fuhrman, Onat Gungor, Tajana Rosing

Intrusion detection systems (IDS) play a crucial role in IoT and network security by monitoring system data and alerting to suspicious activities. Machine learning (ML) has emerged as a promising solution for IDS, offeri…

Continual LearningIntrusion DetectionNovelty Detection