Modern networks are composed of a diverse group of devices and applications, all of which speak different protocols and exhibit varied network behaviors. Understanding these communication patterns is a critical requirement for a network security analyst to enforce effective access control against malicious behavior. The heterogeneity of devices, the diverse communication patterns and the lack of detailed documentation makes it harder to detect malicious behavior. Towards this end, we model the network communication patterns akin to natural language and design a custom transformer architecture to provide the necessary comprehension. We use natural language processing (NLP) transformers for the analysis of network traffic flows, especially for those flows exhibiting high spatial contextualization and temporal correlation. Through extensive experiments, we demonstrate that our model provides a reasonably generic understanding of network flows when applied to solve critical network problems such as application identification, device-type fingerprinting and threat identification. We tested our approach on three diverse data sets with the following results: (a) IoT device-type fingerprinting, an average recall of 97%, (b) application identification, an average recall of 99.6% and (c) threat detection, an average recall of 97%.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Jibber-Jabber!: Encoding the (Un-)Natural Language of Network Devices and Applications

  • Maxwel Bar-on,
  • Kiley Krosky,
  • Federico Larrieu,
  • Bruhadeshwar Bezawada,
  • Indrakshi Ray,
  • Indrajit Ray

摘要

Modern networks are composed of a diverse group of devices and applications, all of which speak different protocols and exhibit varied network behaviors. Understanding these communication patterns is a critical requirement for a network security analyst to enforce effective access control against malicious behavior. The heterogeneity of devices, the diverse communication patterns and the lack of detailed documentation makes it harder to detect malicious behavior. Towards this end, we model the network communication patterns akin to natural language and design a custom transformer architecture to provide the necessary comprehension. We use natural language processing (NLP) transformers for the analysis of network traffic flows, especially for those flows exhibiting high spatial contextualization and temporal correlation. Through extensive experiments, we demonstrate that our model provides a reasonably generic understanding of network flows when applied to solve critical network problems such as application identification, device-type fingerprinting and threat identification. We tested our approach on three diverse data sets with the following results: (a) IoT device-type fingerprinting, an average recall of 97%, (b) application identification, an average recall of 99.6% and (c) threat detection, an average recall of 97%.