Recently, adversarial attacks against machine learning-based network intrusion detection systems (NIDS) have gained significant attention in cybersecurity. This study investigates the transferability of these adversarial attacks in the context of NIDS. In addition, most existing studies in adversarial learning against NIDS adopted attack strategies designed originally for image classification without considering network traffic characteristics. However, this is impractical and will fail in the real world as network traffic features are constrained, and ignoring the functional behavior of the network traffic features leads to invalid network traffic flow or produces adversarial samples that do not retain their original functionality (malicious or benign). To address these issues, we propose a constrained momentum iterative fast gradient sign method (C-MIFGSM) to generate adversarial network flows that can successfully evade an ML-based IDS through transfer-based attacks while preserving the functional behavior of the network traffic. Our approach was validated using several target NIDS models built with the NSLKDD benchmark dataset. Experimental results demonstrate that even without knowledge of the target model and under feature constraints, it is possible to generate adversarial network traffic flows that achieve a high evasion attack success rate against NIDS built with deep learning and classical ML models. For example, the attack degraded the detection rate of the DoS traffic drops from 92.35% to 20.27% for the MLP model with an evasion increase rate of 78.04%.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Investigating the Transferability of Evasion Attacks in Network Intrusion Detection Systems Considering Domain-Specific Constraints

  • Mariama Mbow,
  • Rodrigo Roman,
  • Ayan Seal,
  • Kevin I-Kai Wang,
  • Sraban Kumar Mohanty,
  • Kouichi Sakurai

摘要

Recently, adversarial attacks against machine learning-based network intrusion detection systems (NIDS) have gained significant attention in cybersecurity. This study investigates the transferability of these adversarial attacks in the context of NIDS. In addition, most existing studies in adversarial learning against NIDS adopted attack strategies designed originally for image classification without considering network traffic characteristics. However, this is impractical and will fail in the real world as network traffic features are constrained, and ignoring the functional behavior of the network traffic features leads to invalid network traffic flow or produces adversarial samples that do not retain their original functionality (malicious or benign). To address these issues, we propose a constrained momentum iterative fast gradient sign method (C-MIFGSM) to generate adversarial network flows that can successfully evade an ML-based IDS through transfer-based attacks while preserving the functional behavior of the network traffic. Our approach was validated using several target NIDS models built with the NSLKDD benchmark dataset. Experimental results demonstrate that even without knowledge of the target model and under feature constraints, it is possible to generate adversarial network traffic flows that achieve a high evasion attack success rate against NIDS built with deep learning and classical ML models. For example, the attack degraded the detection rate of the DoS traffic drops from 92.35% to 20.27% for the MLP model with an evasion increase rate of 78.04%.