Skip to Main Content (Press Enter)

Logo UNINSUBRIA
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNINSUBRIA

|

UNI-FIND

uninsubria.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

HERO: From High-dimensional network traffic to zERO-Day attack detection

Articolo
Data di Pubblicazione:
2025
Abstract:
Recent trends in zero-day attack (ZdA) detection use collective anomaly detection to give insights on out-of-distribution anomalies in a zero-shot fashion. Among these, existing frameworks propose the use of specialised labelling strategies to mimic a step-wise abstract anomaly detection algorithm that generalise ZdA-detection over low-dimensional traffic-flow statistics. To enlarge such applicative scenarios, this paper proposes HERO, which is compatible with High-dimensional raw-network traffic captures when performing zERO-day attack detection. To reach convergence over such a high-dimensional and noisy input space, HERO decouples the representation task and the correspondent gradient updates from the discriminative task, following the neural algorithmic reasoning blueprint. Specifically, a neural processor is first trained on the discriminative task using synthetic data, and the weights are then frozen. A second training phase successfully optimises the encoding and decoding networks using raw-traffic captures and the algorithmically-aligned processor. Experiments with well-known intrusion detection datasets demonstrate the crucial advantage of using a two-stage training framework to achieve convergence. To the best of the authors' knowledge, HERO is the first deep learning-based instrument that performs collective anomaly detection and categorisation over raw network traffic on a zero-shot basis, i.e., without using labels.
Tipologia CRIS:
Articolo su Rivista
Keywords:
Zero-day attack detection; Neural algorithmic reasoning; Raw traffic analysis
Elenco autori:
Cevallos, M. Jesus F.; Rizzardi, Alessandra; Sicari, SABRINA SOPHY; COEN PORISINI, Alberto
Autori di Ateneo:
COEN PORISINI ALBERTO
RIZZARDI ALESSANDRA
SICARI SABRINA SOPHY
Link alla scheda completa:
https://irinsubria.uninsubria.it/handle/11383/2193353
Link al Full Text:
https://irinsubria.uninsubria.it//retrieve/handle/11383/2193353/425009/1-s2.0-S1389128625002324-main.pdf
Pubblicato in:
COMPUTER NETWORKS
Journal
  • Accessibilità
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.1.0