Online Network Attack Detection using Statistical Features

Ritesh Ratti, Sukumar Nandi, Sanasam Ranbir Singh · 2021

In recent years, several supervised intrusion detection systems have been proposed. However, these methods require labeled data for training and cannot automatically adapt to frequently changing network traffic scenarios. It is also required for data to be updated periodically and requires the model to be retrained to detect new attacks. This emphasizes the need for the development of unsupervised detection systems that can target zero-day attacks. In this paper, we propose an unsupervised solution that relies on detecting attacks in a discrete-time sliding window using the distance between statistical features. The proposed algorithm utilizes generated cluster profiles and estimates the distance between statistical features to trigger an attack event if it exceeds the predefined threshold. The proposed method was applied to CICIDS-2018 dataset and tested for FTP Brute Force and HTTP Distributed Denial of Service attacks.

Read the paper · More papers on PaperTik