Autoencoder-Based Anomaly Detection in Network Traffic

Krzysztof Korniszuk, Bartosz Sawicki · 2024

Due to the continuously increasing number of resources and data availability in the cloud, the threats related to the security of computer networks and IT systems are critical. Threat detection systems based on deep neural networks and anomaly detection are trained on data related to normal activity so that the network can recognize unusual patterns and behaviours in the event of an attack or an attempt to infiltrate a given IT infrastructure. This paper presents the results of developing a neural network based on an autoencoder for anomaly detection in network packet data. The network was trained on data from the HIKARI-2021 dataset. The autoencoder aims to learn representations of normal network traffic and associate this type of traffic with a minimal reconstruction error. The obtained results were compared with those achieved by authors of other works. High accuracy and sensitivity were achieved at the cost of rather low precision, resulting in many false-positive results. A simple algorithm based on a single threshold value proved efficient but limited in terms of effectiveness. This problem can be resolved by changing the method of calculating the individual components of the vector, using only a subset of features, and deriving multiple vectors, one for each class separately, which has been described and analyzed in more detail.

Read the paper · More papers on PaperTik