Enhancing Network Security Through Deep Learning: Mitigating Feature Engineering and Zero-Day Attacks

Ibrahim El Didi, Fouad Trad, Ali Chehab · 2024

The significant impact of cyber-attacks on their targets, particularly those assisted with ML algorithms, gave rise to a critical need for building a robust detection model based on raw flow traffic without involving feature extraction from the dataset. In recent years, organizations have been working hard to secure their assets from threat agents by implementing IDS and monitoring systems to mitigate these kinds of cyber-attacks, which typically rely on handcrafted input feature engineering. These techniques exhibit a limitation in different scenarios and fail to detect zero-day attacks. To address this limitation, we introduce a deep learning model that inherently learn about features of the raw traffic without any type of preprocessing. We collect streams of raw flows and we train the model to detect malware attacks and to classify their types. The deep learning model extracts the underlying statistics of the network traffic, analyzes the flows without depending on any sort of handcrafted features, and detects the different types of malwares with 100% accuracy, and classify them with an accuracy of 97%. Moreover, the proposed model is able to detect zero-day attacks that it has not seen before with a high accuracy of 99.6%.

Read the paper · More papers on PaperTik