SAWANT: Smart Window Based Anomaly Detection Using Netflow Traffic

Mohammad Hashem Haghighat,Zohreh Abtahi Foroushani,Jun Li
DOI: https://doi.org/10.1109/icct46805.2019.8947103
2019-01-01
Abstract:Network security becomes a big concern nowadays. Although many solutions have been developed to detect network anomalies, the number of successful attacks like DDoS, Phishing, and Spam are boosting dramatically. In this paper, a novel behavior-based method, called SAWANT, is proposed to detect malicious rate of network traffic. SAWANT uses deep learning architecture to analyze netflow data, in which several meaningful attributes are extracted using a sliding window technique. Extracted attributes are then taken to a deep learning structure to identify malicious rate of each window, that represents the rate of abnormal netflow records per the window size. Experimental results over the well-known labeled botnet traffic CTU 13 showed that SAWANT was highly accurate as more than 99% of predicted malicious rates were correct, while it required a very small number of records for training.
What problem does this paper attempt to address?