A Resilient Stream Learning Intrusion Detection Mechanism for Real-Time Analysis of Network Traffic

Eduardo K. Viegas, Altair O. Santin, Nuno Neves, Alysson Bessani, Vilmar Abreu · 2017

The number of novel attacks observed in networked systems increases every day. Due to the large amount of generated data over the network, its storage for further analysis may not be feasible. Moreover, current attacks are becoming more sophisticated, as the attackers are attempting to evade traditional intrusion detection mechanisms by perverting their properties. This paper presents a novel real-time (ongoing) network traffic measurement approach that supports resilient analysis for stream learning intrusion detection. The network data is grouped at runtime according to its characteristics, while each network traffic flow is discretized at regular time intervals. Each network flow is classified by a multi-view stream learning classifiers pool, defining the network flow class through a majority voting approach. The proposal is able to provide resiliency to the classifiers even for the detection of unknown attacks. The evaluation tests for the average operation point (25 views) provides an increase in the system resilience to adversarial attacks of 22 % when compared to traditional approaches. Moreover, in the scalability experiments with a 10-node (single core each) cluster testbed, the network flow measurement solution (1 view) reached 1.38 Gbps throughput, while the proposed resilient stream learning intrusion detection with 25 views reached a throughput of 1.19 Gbps.

Read the paper · More papers on PaperTik