Skip to main content
QUICK REVIEW

[論文レビュー] Recurrent Neural Networks for Enhancement of Signature-based Network Intrusion Detection Systems.

Soroush M. Sohi, Fatemeh Ganji|arXiv (Cornell University)|Jul 9, 2018
Network Security and Intrusion Detection参考文献 50被引用数 8
ひとこと要約

本論文では、再帰的ニューラルネットワーク(RNN)を用いて、多様性を持つ未知の変種の多様性を持つマルウェアを合成し、署名ベースのネットワーク侵入検知システム(NIDS)のための合成署名を生成することで、ゼロデイ攻撃および高度なマルウェアの検出率を著しく向上させることを提案している。RNNによって生成されたパターンで署名データベースを強化することで実現される。

ABSTRACT

Security of information passing through the Internet is threatened by today's most advanced malware ranging from orchestrated botnets to much simpler polymorphic worms. These threads, as examples of zero-day attacks, are able to change their behavior several times at the early phases of their existence to bypass the network intrusion detection systems (NIDS). It is known that even well- designed, and frequently-updated signature-based NIDS cannot detect the zero-day treats due to the lack of an adequate signature database, adaptive to intelligent attacks on the Internet. On the other hand, applying traditional machine learning methods could not narrow this gap. More importantly, having an NIDS, it should be tested on malicious traffic dataset that not only represents known attacks, but also can to some extent reflect the characteristics of unknown, zero-day attacks. Generating such traffic is identified in the literature as one of the main obstacles for evaluating the effectiveness of NIDS. To address these issues, we apply Recurrent Neural Networks (RNNs) known as powerful tools in finding complex patterns and generating similar ones. In this regard, we first examine whether it is possible to generate new, unseen mutants of a polymorphic worm. Our results demonstrate that our synthetic mutants exhibit the same characteristics as the original mutants, i.e., known mutants fed into the RNN. Besides, we assess the ability of RNNs to generate synthetic signatures from the most advanced malware. We claim that by adding the RNN-generated, synthetic signatures to the set of the signatures of a signature-based NIDS it is possible to improve the malware detection rate of that. To support this and evaluate the feasibility of our approach, we conduct extensive experiments and provide exhaustive discussion on our experimental results.

研究の動機と目的

  • 署名ベースのNIDSが最新の署名が不足しているため、ゼロデイ攻撃を検出できないという制限を解消すること。
  • NIDSの効果を評価するための現実的で未知の攻撃トラフィックを生成するという課題を克服すること。
  • RNNが既知の多様性を持つマルウェアの特徴を保持した、合成された未知のマルウェア変種を生成できるかどうかを調査すること。
  • 既存のNIDSにRNNで生成された合成署名を統合することで、検出性能が向上するかを評価すること。
  • 侵入検知システムを強化するために、多様で現実的な攻撃パターンをスケーラブルに生成する方法を提供すること。

提案手法

  • 既知の多様性を持つマルウェアの変種からのネットワークトラフィック特徴のシーケンスを用いてRNNを学習させ、その行動パターンを学習すること。
  • 学習済みのシーケンス分布からサンプリングすることで、訓練済みのRNNを用いて新たな未知の多様性を持つマルウェアの変種を生成すること。
  • 生成された合成変種から署名に似たパターンを抽出し、NIDS用の合成署名を構築すること。
  • RNNで生成された署名を署名ベースのNIDSに統合し、検出性能の向上を評価すること。
  • 実際の攻撃サンプルと比較して、生成された変種の統計的および行動的特徴を検証することで、生成された変種の現実性と多様性を検証すること。
  • 本物のトラフィックと合成トラフィックを用いて広範な実験を行い、強化されたNIDSの検出率と耐性を評価すること。

実験結果

リサーチクエスチョン

  • RQ1RNNは、既知の変種の特徴を保持した、新たな未知の多様性を持つマルウェアの変種を効果的に学習し、生成できるか?
  • RQ2RNNで生成された合成署名は、ゼロデイ攻撃および高度なマルウェアの検出率をどの程度向上させるか?
  • RQ3RNNで生成された合成攻撃トラフィックは、未知のゼロデイ攻撃の特徴を現実的に反映でき、NIDSの効果的評価に役立つか?
  • RQ4RNNで生成された署名を既存のNIDSに統合することで、全体的な性能と誤検出率にどのような影響を与えるか?
  • RQ5RNNは、異なるマルウェアファミリーにわたって、多様で代表的な攻撃パターンを生成する際のスケーラビリティと一般化能力をどの程度有しているか?

主な発見

  • RNNは、訓練に使用された元の多様性を持つマルウェアの変種と同一の行動的および構造的特徴を示す合成変種を効果的に生成した。
  • RNNで生成された合成署名は、既知および以前に観測されていなかった攻撃パターンに対して、署名ベースのNIDSの検出率を顕著に向上させた。
  • RNNで生成された合成攻撃トラフィックは、未知のゼロデイ攻撃の特徴を効果的に反映しており、NIDSの性能評価をより現実的に行えるようになった。
  • 合成署名を既存のNIDSに統合することで、誤検出率に顕著な増加がなく、検出能力が向上した。これは、耐性と実用的妥当性を示している。
  • 本手法は、複数のマルウェアファミリーにわたって多様な攻撃パターンを生成する上でスケーラブルであることが示され、進化する脅威に対するNIDS強化に有効であることが確認された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。