High-speed anomaly traffic detection based on staged frequency domain features

Jiayi Ni,Wei Chen,Jiacheng Tong,Haiyong Wang,Lifa Wu
DOI: https://doi.org/10.1016/j.jisa.2023.103575
IF: 4.96
2023-08-14
Journal of Information Security and Applications
Abstract:Anomaly detection methods based on machine learning assist in identifying attacker behavior concealed in critical infrastructure's high-speed network traffic. However, these methods generally experience problems including a lack of labeled data and poor performance. We suggest a detection method based on staged frequency domain features to address these issues. A small-step sliding window is used in the training phase to fully understand the frequency domain features of the traffic. We suggest SOM-Kmeans, an integrated clustering technique that can accurately distinguish between malicious and benign flows. We evaluate the SOM-Kmeans accuracy using open datasets and assess its effectiveness in a real network environment. The experimental results demonstrate that our method can detect anomaly traffic at high speed without sacrificing detection accuracy.
computer science, information systems
What problem does this paper attempt to address?