Multi-Type Anomaly Detection Based on Raw Network Traffic

Yuwei Sun, Hideya Ochiai, Hiroshi Esaki · 2021

In this article, we presented a visualization method for representing network traffic features using raw data of it. The raw network traffic data was divided into regulated segments. By employing a supervised neural network and an expert-knowledge based labeling method, model training was conducted based on a dataset covering two weeks' network traffic, where the first week's data was employed as the training set and the second week's data was used as the validation set. At last, we achieved validation precision scores of 0.980 for detecting the ARP flooding, 0.800 and 0.815 for detecting the malicious SMB and TCP SYN flooding respectively.

Read the paper · More papers on PaperTik