• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Unsupervised Anomaly Detection and Explanation in Network Traffic with Transformers
 
  • Details
  • Full
Options
2024
Journal Article
Title

Unsupervised Anomaly Detection and Explanation in Network Traffic with Transformers

Abstract
Deep learning-based autoencoders represent a promising technology for use in network-based attack detection systems. They offer significant benefits in managing unknown network traces or novel attack signatures. Specifically, in the context of critical infrastructures, such as power supply systems, AI-based intrusion detection systems must meet stringent requirements concerning model accuracy and trustworthiness. For the intrusion response, the activation of suitable countermeasures can greatly benefit from additional transparency information (e.g., attack causes). Transformers represent the state of the art for learning from sequential data and provide important model insights through the widespread use of attention mechanisms. This paper introduces a two-stage transformer-based autoencoder for learning meaningful information from network traffic at the packet and sequence level. Based on this, we present a sequential attention weight perturbation method to explain benign and malicious network packets. We evaluate our method against benchmark models and expert-based explanations using the CIC-IDS-2017 benchmark dataset. The results show promising results in terms of detecting and explaining FTP and SSH brute-force attacks, highly outperforming the results of the benchmark model.
Author(s)
Kummerow, Andre  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Esrom, Abrha
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Eisenbach, Markus  
Technische Universität Ilmenau
Rösch, Dennis  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Journal
Electronics. Online journal  
Open Access
DOI
10.3390/electronics13224570
Language
English
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Keyword(s)
  • ZsiF

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024