A method of network traffic anomaly detection based on Packet Window Transformer
Cheng Fang, Wenjie Mi, Ping Han, Lidong Zhai · 2022
As Web 2.0 applications grow in popularity, Internet is playing an increasingly significant role in our lives. People exchange information and share resources anytime and anywhere through the Internet. In other words, the Internet is the driving force behind new technologies like 5G, blockchain, Internet of Things, etc. At the same time, Internet attacks based on vulnerabilities and security flaws have gradually increased. Attackers hide their real IP addresses to find and analyze target hosts, send some fake malicious packets to the system vulnerabilities. With the emergence and popularity of new Internet applications, advanced persistent network attacks are also increasing, which brings new challenges to network security. At present, most intrusion detections only focus on multi-dimensional traffic features but ignore the spatio-temporal features of network traffic. In this paper, a packet window based is proposed to transform network flow data into multiple window blocks. The feature matrix formed by window blocks can better show the local sequence relationship. Then we propose an improved Transformer sequence analysis model on these feature matrix to network traffic anomaly detection. Our method can exploit the multi-dimensional traffic features and model the time series relationship between network traffic. Empirical results on public IDS2017 dataset show that our approach achieves leading accuracy though integrating spatio-temporal features. It has 96.1% accuracy and 95.6% F1 score. Compared to other state-of-the-art deep learning models, Our model achieves excellent results.