TY - GEN
T1 - AGAE
T2 - 8th Asia-Pacific Web and Web-Age Information Management Joint International Conference on Web and Big Data, APWeb-WAIM 2024
AU - Wang, Hao
AU - Wang, Ye
AU - Gu, Zhaoquan
AU - Jia, Yan
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2024.
PY - 2024
Y1 - 2024
N2 - Nowadays, In order to protect the privacy and security of network users, network traffic is extensively encrypted. However, encrypted traffic can also be exploited by attackers to conceal their malicious activities. Moreover, existing approaches heavily rely on supervised learning and labeled datasets. Thus, effectively detecting malicious traffic with limited data remains an unresolved issue. In this paper, we propose AGAE, an unsupervised anomaly detection system for detecting malicious traffic, based on the Attribute Graph AutoEncoder we designed. We innovatively analyze the convergence and reusability of network attacks, and design AGAE by using these two characteristics. We conduct extensive experiments to evaluate the performance of AGAE. The experimental results illustrate that the AGAE achieves average AUC of 0.961. And the average F1 achieves 0.974, which outperform the state-of-the-art methods. In particular, AGAE has stronger detection capabilities against traditional brute force attacks and encrypted flooding traffic.
AB - Nowadays, In order to protect the privacy and security of network users, network traffic is extensively encrypted. However, encrypted traffic can also be exploited by attackers to conceal their malicious activities. Moreover, existing approaches heavily rely on supervised learning and labeled datasets. Thus, effectively detecting malicious traffic with limited data remains an unresolved issue. In this paper, we propose AGAE, an unsupervised anomaly detection system for detecting malicious traffic, based on the Attribute Graph AutoEncoder we designed. We innovatively analyze the convergence and reusability of network attacks, and design AGAE by using these two characteristics. We conduct extensive experiments to evaluate the performance of AGAE. The experimental results illustrate that the AGAE achieves average AUC of 0.961. And the average F1 achieves 0.974, which outperform the state-of-the-art methods. In particular, AGAE has stronger detection capabilities against traditional brute force attacks and encrypted flooding traffic.
KW - Anomaly detection
KW - Autoencoder
KW - Malicious Traffic detection
UR - https://www.scopus.com/pages/publications/85203129628
U2 - 10.1007/978-981-97-7241-4_28
DO - 10.1007/978-981-97-7241-4_28
M3 - 会议稿件
AN - SCOPUS:85203129628
SN - 9789819772407
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 448
EP - 464
BT - Web and Big Data - 8th International Joint Conference, APWeb-WAIM 2024, Proceedings
A2 - Zhang, Wenjie
A2 - Yang, Zhengyi
A2 - Wang, Xiaoyang
A2 - Tung, Anthony
A2 - Zheng, Zhonglong
A2 - Guo, Hongjie
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 30 August 2024 through 1 September 2024
ER -