Anomaly detection based on feature extraction of unknown protocol payload format
Zefan Song, Bin Wu · 2020 IEEE 5th Information Technology and Mechatronics Engineering Conference (ITOEC) · 2020
Intrusion detection technology is mainly divided into two categories: Misuse Detection and Anomaly Detection. Misuse Detection cannot detect unknown attacks, and the rate of false negatives is high. Abnormal Detection's false alarms rate is high, and practical applications are few. The current mainstream intrusion detection systems (IDS) consider application scenarios that are common network environments and pursue high cost performance. To make up for the deficiencies of IDS, this paper proposes an attack detection in special network, which exist a large number of user-defined unknown protocols. By extracting features from the unknown protocols, the characteristics of the unknown protocol format are obtained, and anomaly detection is performed based on this characteristic. This paper first demonstrates the feature extraction technology of unknown protocols, explains mathematically how to obtain the protocol format information of each layer of the unknown protocol, then conducts simulation experiments and compares the detection results with ordinary misuse detection and anomaly detection.