Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

An Ensemble of Text Convolutional Neural Networks and Multi-Head Attention Layers for Classifying Threats in Network Packetsopen access

Authors
Kim, HyeonminYoon, Young
Issue Date
Oct-2023
Publisher
MDPI
Keywords
network threat classification; multi-head attention; ensemble machine learning; packet payload processing
Citation
ELECTRONICS, v.12, no.20
Journal Title
ELECTRONICS
Volume
12
Number
20
URI
https://scholarworks.bwise.kr/hongik/handle/2020.sw.hongik/31843
DOI
10.3390/electronics12204253
ISSN
2079-9292
Abstract
Using traditional methods based on detection rules written by human security experts presents significant challenges for the accurate detection of network threats, which are becoming increasingly sophisticated. In order to deal with the limitations of traditional methods, network threat detection techniques utilizing artificial intelligence technologies such as machine learning are being extensively studied. Research has also been conducted on analyzing various string patterns in network packet payloads through natural language processing techniques to detect attack intent. However, due to the nature of packet payloads that contain binary and text data, a new approach is needed that goes beyond typical natural language processing techniques. In this paper, we study a token extraction method optimized for payloads using n-gram and byte-pair encoding techniques. Furthermore, we generate embedding vectors that can understand the context of the packet payload using algorithms such as Word2Vec and FastText. We also compute the embedding of various header data associated with packets such as IP addresses and ports. Given these features, we combine a text 1D CNN and a multi-head attention network in a novel fashion. We validated the effectiveness of our classification technique on the CICIDS2017 open dataset and over half a million data collected by The Education Cyber Security Center (ECSC), currently operating in South Korea. The proposed model showed remarkable performance compared to previous studies, achieving highly accurate classification with an F1-score of 0.998. Our model can also preprocess and classify 150,000 network threats per minute, helping security agents in the field maximize their time and analyze more complex attack patterns.
Files in This Item
There are no files associated with this item.
Appears in
Collections
ETC > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Yoon, Young photo

Yoon, Young
Engineering (Department of Computer Engineering)
Read more

Altmetrics

Total Views & Downloads

BROWSE