Collective Anomaly Detection Based on Long Short-Term Memory Recurrent Neural Networks

被引:151
作者
Bontemps, Loic [1 ]
Van Loi Cao [1 ]
McDermott, James [1 ]
Nhien-An Le-Khac [1 ]
机构
[1] Univ Coll Dublin, Dublin, Ireland
来源
FUTURE DATA AND SECURITY ENGINEERING, FDSE 2016 | 2016年 / 10018卷
关键词
Long short-term memory; Recurrent neural network; Collective anomaly detection;
D O I
10.1007/978-3-319-48057-2_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection for computer network systems is becoming one of the most critical tasks for network administrators today. It has an important role for organizations, governments and our society due to the valuable resources hosted on computer networks. Traditional misuse detection strategies are unable to detect new and unknown intrusion types. In contrast anomaly detection in network security aims to distinguish between illegal or malicious events and normal behavior of network systems. Anomaly detection can be considered as a classification problem where it builds models of normal network behavior, which it uses to detect new patterns that significantly deviate from the model. Most of the current research on anomaly detection is based on the learning of normal and anomaly behaviors. They have no memory that is they do not take into account previous events classify new ones. In this paper, we propose a real time collective anomaly detection model based on neural network learning. Normally a Long Short-Term Memory Recurrent Neural Network (LSTM RNN) is trained only on normal data and it is capable of predicting several time steps ahead of an input. In our approach, a LSTM RNN is trained with normal time series data before performing a live prediction for each time step. Instead of considering each time step separately, the observation of prediction errors from a certain number of time steps is now proposed as a new idea for detecting collective anomalies. The prediction errors from a number of the latest time steps above a threshold will indicate a collective anomaly. The model is built on a time series version of the KDD 1999 dataset. The experiments demonstrate that it is possible to offer reliable and efficient collective anomaly detection.
引用
收藏
页码:141 / 152
页数:12
相关论文
共 14 条
[1]   A survey of network anomaly detection techniques [J].
Ahmed, Mohiuddin ;
Mahmood, Abdun Naser ;
Hu, Jiankun .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 60 :19-31
[2]  
[Anonymous], 1999, KDD Cup Dataset
[3]  
Bhattacharyya D. K., 2013, Network Anomaly Detection: A Machine Learning Perspective
[4]  
Chmielewski A, 2006, P INT MULT COMP SCI, P9
[5]  
Hawkins S., 2002, INT C DAT WAR KNOWL, P170, DOI DOI 10.1007/3-540-46145-0_17
[6]  
Hochreiter S, 1997, NEURAL COMPUT, V9, P1735, DOI [10.1162/neco.1997.9.1.1, 10.1007/978-3-642-24797-2]
[7]  
Lee W., 2000, ACM Transactions on Information and Systems Security, V3, P227, DOI 10.1145/382912.382914
[8]   Network Anomaly Detection Based on Wavelet Analysis [J].
Lu, Wei ;
Ghorbani, Ali A. .
EURASIP JOURNAL ON ADVANCES IN SIGNAL PROCESSING, 2009,
[9]  
Malhotra P., 2015, ESANN, Vvol 2015, pp 89
[10]  
Marchi E, 2015, IEEE IJCNN