Evaluation of feature learning for anomaly detection in network traffic

[EN] The application of anomaly detection approaches to network intrusion detection in real scenarios is difficult. The ability of techniques such as deep learning to estimate new data representations with higher levels of abstraction can be useful to address data analysis of network traffic data. F...

Descripción completa

Detalles Bibliográficos
Autores: Pérez López, Daniel, Alonso Castro, Serafín, Morán Álvarez, Antonio, Prada Medrano, Miguel Ángel, Fuertes Martínez, Juan José, Domínguez González, Manuel
Tipo de recurso: artículo
Estado:Versión enviada para evaluación y publicación
Fecha de publicación:2021
País:España
Institución:Universidad de León
Repositorio:BULERIA. Repositorio Institucional de la Universidad de León
OAI Identifier:oai:buleria.unileon.es:10612/26787
Acceso en línea:https://hdl.handle.net/10612/26787
Access Level:acceso abierto
Palabra clave:Ingeniería de sistemas
Anomaly detection
Feature learning
Network intrusion detection
Descripción
Sumario:[EN] The application of anomaly detection approaches to network intrusion detection in real scenarios is difficult. The ability of techniques such as deep learning to estimate new data representations with higher levels of abstraction can be useful to address data analysis of network traffic data. For that reason, the performance of different anomaly detection techniques on feature representations obtained by an autoencoder and a variational autoencoder is compared. We have employed a variety of well-known anomaly detection algorithms, which addresses intrusion detection as a semi-supervised problem where patterns that deviate from a baseline model, estimated only from normal traffic, are labelled as anomalous. Furthermore, this assessment is performed on four publicly available benchmarks. The results show that the effect of feature representation on performance is highly dependent on the anomaly detection technique.