Preliminary Results in Using Attention for Increasing Attack Identification Efficiency
Tanwir Ahmad, Dragoş Truşcan, Jüri Vain · 2023
In previous work, we proposed an end-to-end intrusion early detection system to identify network attacks in real-time before they complete and could cause more damage to the system under attack. To implement the approach, we have used a deep neural network which was trained in a supervised manner to extract relevant features from raw network traffic in order to classify network flows into different types of attacks. In this work, we discuss the initial results of the benefits that an attention mechanism brings to the classification performance and the capacity of the network to detect attacks earlier. We empirically evaluate our approach on the CICIDS2017 dataset. Preliminary results show that the attention mechanism improves both the balanced accuracy of the classifier as well as the early detection of attacks.