Recent trends in zero-day attack (ZdA) detection use collective anomaly detection to give insights on out-of-distribution anomalies in a zero-shot fashion. Among these, existing frameworks propose the use of specialised labelling strategies to mimic a step-wise abstract anomaly detection algorithm that generalise ZdA-detection over low-dimensional traffic-flow statistics. To enlarge such applicative scenarios, this paper proposes HERO, which is compatible with High-dimensional raw-network traffic captures when performing zERO-day attack detection. To reach convergence over such a high-dimensional and noisy input space, HERO decouples the representation task and the correspondent gradient updates from the discriminative task, following the neural algorithmic reasoning blueprint. Specifically, a neural processor is first trained on the discriminative task using synthetic data, and the weights are then frozen. A second training phase successfully optimises the encoding and decoding networks using raw-traffic captures and the algorithmically-aligned processor. Experiments with well-known intrusion detection datasets demonstrate the crucial advantage of using a two-stage training framework to achieve convergence. To the best of the authors' knowledge, HERO is the first deep learning-based instrument that performs collective anomaly detection and categorisation over raw network traffic on a zero-shot basis, i.e., without using labels.

HERO: From High-dimensional network traffic to zERO-Day attack detection

Rizzardi Alessandra
Secondo
;
Sicari Sabrina
Penultimo
;
Coen-Porisini Alberto
Ultimo
2025-01-01

Abstract

Recent trends in zero-day attack (ZdA) detection use collective anomaly detection to give insights on out-of-distribution anomalies in a zero-shot fashion. Among these, existing frameworks propose the use of specialised labelling strategies to mimic a step-wise abstract anomaly detection algorithm that generalise ZdA-detection over low-dimensional traffic-flow statistics. To enlarge such applicative scenarios, this paper proposes HERO, which is compatible with High-dimensional raw-network traffic captures when performing zERO-day attack detection. To reach convergence over such a high-dimensional and noisy input space, HERO decouples the representation task and the correspondent gradient updates from the discriminative task, following the neural algorithmic reasoning blueprint. Specifically, a neural processor is first trained on the discriminative task using synthetic data, and the weights are then frozen. A second training phase successfully optimises the encoding and decoding networks using raw-traffic captures and the algorithmically-aligned processor. Experiments with well-known intrusion detection datasets demonstrate the crucial advantage of using a two-stage training framework to achieve convergence. To the best of the authors' knowledge, HERO is the first deep learning-based instrument that performs collective anomaly detection and categorisation over raw network traffic on a zero-shot basis, i.e., without using labels.
2025
2025
Zero-day attack detection; Neural algorithmic reasoning; Raw traffic analysis
Cevallos, M. Jesus F.; Rizzardi, Alessandra; Sicari, SABRINA SOPHY; COEN PORISINI, Alberto
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S1389128625002324-main.pdf

accesso aperto

Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 4.56 MB
Formato Adobe PDF
4.56 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11383/2193353
 Attenzione

L'Ateneo sottopone a validazione solo i file PDF allegati

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact