Utilizing Deep Learning Techniques to Detect Zero Day Exploits in Network Traffic Flows

Benjamin Drozdenko, Makia S. Powell · 2022 IEEE 13th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON) · 2022

In recent times, the cybersecurity of naval systems has become a major concern; in particular, there is an increased need for network traffic analysis and detecting the presence of threat actors. In industry, commercial intrusion detection and prevention systems have been extremely useful of protecting systems on the general internet; for submarine networks, a more targeted approach is clearly needed. To accommodate large amounts of traffic, flow analysis using such technologies as NetFlow and sFlow have shown clear advantage for real-time concerns. However, for submarine networks, the question of which parameter settings are most ideal and how to use the flow data most effectively still do not have clear answers. In this technical memo, we present a deep learning approach to analyzing flow traffic. Whereas deep neural networks would take considerable time to process raw network PCAP files, training a deep neural network on flow data would show significant time improvement in recognizing modern cyberattacks. Our results aim to show which flow parameter and neural network hyperparameter settings are optimal for recognizing and reacting to various cyberattacks in minimal time.

Read the paper · More papers on PaperTik