Bài viết
Phương pháp học biểu diễn ẩn với số lượng nhãn hữu hạn cho phát hiện bất thường mạng IoT
- Nguyễn Hữu Nội (VN)
- Trân Nguyên Ngọc (VN)
Tóm tắt
Tóm tắt— Phát hiện mã độc là một thách thức lớn trong thời đại hiện nay, đặc biệt là đối với các thiết bị IoT. Các nghiên cứu trước đây của nhóm tác giả đã áp dụng các kỹ thuật phân tích để giảm kích thước dữ liệu và trích xuất thông tin có giá trị. Tuy nhiên, hầu hết các nghiên cứu đó dựa vào một lượng lớn các điểm ngoại lai để thực hiện phát hiện bất thường. Trong bài báo này, nhóm tác giả đề xuất một phương pháp cải tiến dựa trên mạng FeaWAD (FeaWAD*) để cải thiện phương pháp biểu diễn dữ liệu. Mô hình này chỉ yêu cầu một phần nhỏ các bất thường để huấn luyện. Nhóm tác giả đánh giá phương pháp FeaWAD trên tập dữ liệu N-BaIoT với nhiều kịch bản kiểm tra khác nhau để phát hiện các cuộc tấn công đã biết cũng như các cuộc tấn công chưa biết. Kết quả thực nghiệm cho thấy phương pháp FeaWAD* cho kết quả tốt hơn mô hình gốc FeaWAD và các phương pháp phát hiện bất thường phổ biến khác như Isolation Forest, Local Outlier Factor và One-class Support Vector Machine. Đồng thời, nhóm tác giả cũng đánh giá hiệu quả của mô hình dựa trên thời gian để đánh giá khả năng áp dụng vào thực tế.
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Nguyễn Hữu Nội, Trân Nguyên Ngọc (2023). Phương pháp học biểu diễn ẩn với số lượng nhãn hữu hạn cho phát hiện bất thường mạng IoT. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 3(20), 14-22. https://doi.org/10.54654/isj.v3i20.986
Tài liệu tham khảo
- 1.Y. Zhou, X. Song, Y. Zhang, F. Liu, C. Zhu, and L. Liu, “Feature Encoding with AutoEncoders for Weakly-supervised Anomaly Detection,” IEEE Trans Neural Netw Learn Syst, vol. 33, no. 6, pp. 2454–2465, May 2021, doi: 10.1109/TNNLS.2021.3086137.
- 2.A. E. Omolara et al., “The internet of things security: A survey encompassing unexplored areas and new insights,” Comput Secur, vol. 112, p. 102494, Jan. 2022, doi: 10.1016/J.COSE.2021.102494.
- 3.D. T. Son, N. T. K. Tram, and P. M. Hieu, “Deep Learning Techniques to Detect Botnet,” Journal of Science and Technology on Information security, vol. 1, no. 15, pp. 85–91, Jun. 2022, doi: 10.54654/ISJ.V1I15.846.
- 4.N. Hung, Đ. Mai, N. T.-J. of S. and T. on, and undefined 2023, “Network attack classification framework based on Autoencoder model and online stream analysis technology,” isj.vn, Accessed: Sep. 26, 2023. [Online]. Available: https://isj.vn/index.php/journal_STIS/article/view/938
- 5.J. Liu et al., “Deep anomaly detection in packet payload,” Neurocomputing, vol. 485, pp. 205–218, May 2022, doi: 10.1016/J.NEUCOM.2021.01.146.
- 6.C. Qiu, T. Pfrommer, M. Kloft, S. Mandt, and M. Rudolph, “Neural Transformation Learning for Deep Anomaly Detection Beyond Images.” PMLR, pp. 8703–8714, Jul. 01, 2021. Accessed: Sep. 14, 2023. [Online]. Available: https://proceedings.mlr.press/v139/qiu21a.html
- 7.V. L. Cao, M. Nicolau, and J. McDermott, “Learning Neural Representations for Network Anomaly Detection,” IEEE Trans Cybern, vol. 49, no. 8, pp. 3074–3087, Aug. 2019, doi: 10.1109/TCYB.2018.2838668.
- 8.H. N. Nguyen, N. N. Tran, T. H. Hoang, and V. L. Cao, “Denoising Latent Representation with SOMs for Unsupervised IoT Malware Detection,” SN Computer Science 2022 3:6, vol. 3, no. 6, pp. 1–15, Sep. 2022, doi: 10.1007/S42979-022-01344-1.
- 9.G. Pang, C. Shen, and A. Van Den Hengel, “Deep anomaly detection with deviation networks,” Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 353–362, Jul. 2019, doi: 10.1145/3292500.3330871.
- 10.L. Ruff et al., “DEEP SEMI-SUPERVISED ANOMALY DETECTION,” in 8th International Conference on Learning Representations, ICLR 2020, 2020.
- 11.T. Shenkar and L. Wolf, “ANOMALY DETECTION FOR TABULAR DATA WITH INTERNAL CONTRASTIVE LEARNING,” in ICLR 2022 - 10th International Conference on Learning Representations, 2022.
- 12.N. T. Dung, N. V. Quân, and N. V. Hùng, “Application of deep learning model in network reconnaissance attack detection,” Journal of Science and Technology on Information security, vol. 2, no. 16, pp. 60–72, Feb. 2022, doi: 10.54654/ISJ.V1I16.922.
- 13.B. Zong et al., “Deep autoencoding Gaussian mixture model for unsupervised anomaly detection,” in 6th International Conference on Learning Representations, ICLR 2018 - Conference Track Proceedings, 2018.
- 14.G. Pang, L. Chen, L. Cao, and H. Liu, “Learning representations of ultrahigh-dimensional data for random distance-based outlier detection,” Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 2041–2050, Jul. 2018, doi: 10.1145/3219819.3220042.
- 15.C. Zhou and R. C. Paffenroth, “Anomaly detection with robust deep autoencoders,” Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, vol. Part F129685, pp. 665–674, Aug. 2017, doi: 10.1145/3097983.3098052.
- 16.H. Xu et al., “Unsupervised Anomaly Detection via Variational Auto-Encoder for Seasonal KPIs in Web Applications,” The Web Conference 2018 - Proceedings of the World Wide Web Conference, WWW 2018, pp. 187–196, Apr. 2018, doi: 10.1145/3178876.3185996.
- 17.M. A. Siddiqui, R. Wright, A. Fern, A. Theriault, T. G. Dietterich, and D. W. Archer, “Feedback-guided anomaly discovery via online optimization,” Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 2200–2209, Jul. 2018, doi: 10.1145/3219819.3220083.
- 18.L. Ruff et al., “Deep one-class classification,” in 35th International Conference on Machine Learning, ICML 2018, 2018.
- 19.Y. Meidan et al., “N-baiot—network-based detection of iot botnet attacks using deep autoencoders,” IEEE Pervasive Comput, vol. 17, no. 3, pp. 12–22, 2018.