Raw Packet Data Ingestion with Transformers for Malicious Activity Classifications
Nitin Sharan, Thomas Quig, Eric Goodman, Yung Ryn Choe, Dalton A. Brucker-Hahn · 2023
Traffic diversity, novel attacks, and sheer volume of network traffic creates a significant challenge in detecting and identifying malicious actions against a network. Due to these factors, human auditing of network events is unfeasible, requiring advanced approaches, such as machine learning techniques. Furthermore, the increasing novelty of network attacks render traditional filtering mechanisms unable to handle such threats. In this paper, we propose a novel, natural language processing approach to detecting malicious, network-based attacks, using ByT5. Our approach classifies network packet data as malicious or benign. ByT5 is a token-free sequence to sequence model, enabling the model to take in raw packet streams and classify the packets without feature extraction or preprocessing via an encoding schema. The results of our approach in classifying traffic as benign or malicious indicates promising results. Namely, when applied to the ISOT dataset, our approach achieves a maximal recall of 0.834 and a maximal F1 score of 0.693.