Anomaly Traffic Detection with Verifiable Interpretation in Industrial Networks

Hongyu Zhu, Jianwei Tian, Zheng Tian, Shi Zhu, Haozhi Li, Yuxiang Zhang · 2021 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech) · 2021

Anomaly traffic detection in industrial networks plays a key role in protecting critical infrastructure assets and private data. Deep Neural Networks (DNNs) based anomaly traffic detection has received increased attention in recent work. Although their high accuracy, the lack of interpretability of deep learning models has seriously hindered its application in industrial high-risk decision-making fields. To address this issue, this paper presents a framework for DNN based interpretable anomaly traffic detection and interpretation verification based on an adversarial approach. When the DNN detects an anomalous event, in addition to the prediction, the framework provides the user with the confidence of the prediction and the input features that were relevant in making the prediction. In order to verify the validity of the interpretation, we use an adversarial method to find the minimum modifications of real features that make the classification change. This paper implements an experimental evaluation of the presented framework on the benchmark CICDDoS2019 dataset and KDD-NSL dataset for attack detection. The experimental results which are shown using intuitive visualizations prove the validity of the interpretation presented in this paper.

Read the paper · More papers on PaperTik