错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Proposal of Adversarial Attack Traffic Detection Using Adversarial Attack Techniques for Network Intrusion Detection System

  • Taisei Watanabe,
  • Eiichiro Kodama,
  • Bhed Bahadur Bista,
  • Jiahong Wang,
  • Toyoo Takata

摘要

Network Intrusion Detection Systems (NIDS) based on machine learning have attracted much attention. However, such machine learning models have a vulnerability: it is possible to create input that leads to detection failure. This vulnerability can be exploited by an attacker to create adversarial attack traffic (AdvAT) to bypass NIDS. Wang et al. proposed an AdvAT detection method, MANDA, which combines a manifold-based score that exploits the fact that AdvAT belongs to the manifold of the original attack class and a decision boundary-based score that exploits the fact that AdvAT is located near the decision boundary of NIDS. However, we found that MANDA’s detection performance degrades in situations where AdvATs of various perturbation magnitudes are mixed, and that it cannot cope with AdvATs when the magnitude of the perturbation added to the AdvAT is not known a priori. In order to solve their issues, we propose a new AdvAT detection method that introduces a new score calculated using an adversarial attack method. The evaluation of the proposed method in a situation where AdvATs with various perturbation magnitudes are mixed together showed that the AUC and the correct response rate were 0.9987 and 99.01%, respectively, and the detection performance was successfully improved.