Detection and Classification of Network Events in LAN Using CNN

Yuwei Sun, Hiroshi Esaki, Hideya Ochiai · 2019

Security of local area network (LAN) attracts many attentions in recent years. A malware delivered, for example by phishing e-mails, intrudes and expands into the other hosts in the LAN easily these days. Previous works have taken machine learning approach to detect anomaly caused by malware's behavior. However, there are still not so many researches that try to clarify the reasons of such anomaly, i.e., explanation of the anomaly causes. In this research, we propose a method using convolutional neural network (CNN) with a refined normalization function and learning function to detect and also classify different events happened in the LAN. We use Hilbert Curve, array exchange, and projection to generate feature maps to represent protocol information of events within a predetermined time span. We have tested our scheme on three different active network cases. We have obtained an average recall rate of 76% for detecting and classifying 8 types of events categorized as normal, arp scan, tcp scan, scan of tcp port 23, scan of tcp port 80, udp scan, scan of udp port 137, scan of udp port 1900 for those active networks.

Read the paper · More papers on PaperTik