TPE-MHA: A Malicious Traffic Detection Model Based on Time Position Encoding and Multi-head Attention
Yi Zhai, Bin Lu, Xiaowei Li · 2021 IEEE 21st International Conference on Communication Technology (ICCT) · 2021
The proliferation of malicious software brings severe challenges for network security, hence there is an immediate need for devising efficient anomaly detection caused by malicious behavior. Traditional machine learning-based anomaly detections are highly dependent on expert knowledge to extract the features. This is however a time-consuming and costly process. Deep learning-based anomaly detection techniques have been applied to build end-to-end malicious traffic detection models. Since most of these works are based on image recognition or text classification methods they ignore the structural features of the network traffic and unbalanced distributed feature of the data packets in the time domain. This reduces learning capability and performance of these models. To address these issues, we analyze the hierarchical structure of the traffic features and propose a new time position encoding technique based on the similarity between network traffic and text language. Using this approach we then devise the Time Position Encoding and Multihead Attention (TPE-MHA) as an end-to-end detection model for traffic anomaly detection. TPE-MHA is based on the Multi-head Attention mechanism and does not require prior knowledge of network protocol. Experimental results based on public datasets of USTC-TFC2016 and CICIDS2017 confirm the validity and efficiency of the proposed model.