XGBoosted Misuse Detection in LAN-Internal Traffic Dataset

Zhiqing Zhang, Pawissakan Chirupphapa, Hiroshi Esaki, Hideya Ochiai · 2020

There is an apparently increasing trend of cyber attacks towards LANs in recent years. It is getting more important to monitor the behaviors in LAN and detect intrusions rapidly and accurately. However, there are few studies for the behavior of LAN-internal communications. These works are faced with problems including (1) the lack of popular datasets especially captured from real-world LAN-internal communications, and (2) the lack of well-designed feature extraction for LAN communications. In this paper we propose (1) LAN traffic dataset with protocol based features and labels, and (2) XGBoost based misuse intrusion detection for LAN. After deploying 45 monitoring devices in distributed LANs in 10 countries, we detect malicious hosts from total 52,463 hosts appearing during Nov.1st, 2019 to May.5th, 2020 by extracting their behavioral features on each protocol. Evaluation results demonstrate that our misuse detection performs 97.5% in overall precision and 97.5% in overall recall. Besides, we also discovered that ARP, MDNS and NBNS are the top 3 protocols that influence the intrusion detection most in LAN.

Read the paper · More papers on PaperTik