NERO: NEural algorithmic reasoning for zeRO-day attack detection in the IoT: A hybrid approach

Jesús F. Cevallos M.,Alessandra Rizzardi,Sabrina Sicari,Alberto Coen Porisini
DOI: https://doi.org/10.1016/j.cose.2024.103898
IF: 5.105
2024-05-15
Computers & Security
Abstract:Anomaly detection approaches for network intrusion detection learn to identify deviations from normal behavior on a data-driven basis. However, current approaches strive to infer the degree of abnormality of out-of-distribution samples when these appertain to different zero-day attacks. Inspired by the successes of the neural algorithmic reasoning paradigm to leverage the generalization of rule-based behavior, this paper presents a deep learning strategy for solving zero-day network attack detection and categorization. Moreover, focusing on the particular scenario of the Internet of Things (IoT), the privacy preservation requirement may imply a low training data regime for any learning algorithm. To this respect, the presented framework uses metric-based meta-learning to achieve few-shot learning capabilities. The presented pipeline is called NERO , as it imports the encode-process-decode architecture from the NE ural algorithmic reasoning blueprint to converge ze RO -day attack detection policies within constrained training data.
computer science, information systems
What problem does this paper attempt to address?