English
Related papers

Related papers: ENCODE: Encoding NetFlows for Network Anomaly Dete…

200 papers

We present a study of deep learning applied to the domain of network traffic data forecasting. This is a very important ingredient for network traffic engineering, e.g., intelligent routing, which can optimize network performance,…

Machine Learning · Computer Science 2019-09-13 Benedikt Pfülb , Christoph Hardegen , Alexander Gepperth , Sebastian Rieger

Intrusion detection into computer networks has become one of the most important issues in cybersecurity. Attackers keep on researching and coding to discover new vulnerabilities to penetrate information security system. In consequence…

Cryptography and Security · Computer Science 2020-12-17 Sergio Hidalgo-Espinoza , Kevin Chamorro-Cupueran , Oscar Chang-Tortolero

Cybersecurity systems are continuously producing a huge number of time-stamped events in the form of high-order tensors, such as {count; time, port, flow duration, packet size, . . . }, and so how can we detect anomalies/intrusions in real…

Machine Learning · Computer Science 2025-03-04 Kota Nakamura , Koki Kawabata , Shungo Tanaka , Yasuko Matsubara , Yasushi Sakurai

Network embedding which encodes all vertices in a network as a set of numerical vectors in accordance with it's local and global structures, has drawn widespread attention. Network embedding not only learns significant features of a…

Physics and Society · Physics 2017-04-20 Weiwei Gu , Li Gong , Xiandao Lou , Jiang Zhang

The explosive growth of system logs makes streaming compression essential, yet existing log anomaly detection (LAD) methods incur severe pre-processing overhead by requiring full decompression and parsing. We introduce CLAD, the first deep…

Machine Learning · Computer Science 2026-04-15 Benzhao Tang , Shiyu Yang

Identifying threats in a network traffic flow which is encrypted is uniquely challenging. On one hand it is extremely difficult to simply decrypt the traffic due to modern encryption algorithms. On the other hand, passing such an encrypted…

Cryptography and Security · Computer Science 2020-11-10 Syed Muhammad Kumail Raza , Juan Caballero

Google uses continuous streams of data from industry partners in order to deliver accurate results to users. Unexpected drops in traffic can be an indication of an underlying issue and may be an early warning that remedial action may be…

Machine Learning · Statistics 2017-08-15 Dominique T. Shipmon , Jason M. Gurevitch , Paolo M. Piselli , Stephen T. Edwards

Machine Learning (ML) techniques are becoming an invaluable support for network intrusion detection, especially in revealing anomalous flows, which often hide cyber-threats. Typically, ML algorithms are exploited to classify/recognize data…

Cryptography and Security · Computer Science 2021-04-13 Mario Di Mauro , Giovanni Galatro , Giancarlo Fortino , Antonio Liotta

In this paper, we propose a new method for detecting unauthorized network intrusions, based on a traffic flow model and Cisco NetFlow protocol application. The method developed allows us not only to detect the most common types of network…

Cryptography and Security · Computer Science 2017-02-20 Aleksey A. Galtsev , Andrei M. Sukhov

The widespread adoption of encrypted communication protocols such as HTTPS and TLS has enhanced data privacy but also rendered traditional anomaly detection techniques less effective, as they often rely on inspecting unencrypted payloads.…

Cryptography and Security · Computer Science 2025-05-23 Kalindi Singh , Aayush Kashyap , Aswani Kumar Cherukuri

A Normalizing Flow computes a bijective mapping from an arbitrary distribution to a predefined (e.g. normal) distribution. Such a flow can be used to address different tasks, e.g. anomaly detection, once such a mapping has been learned. In…

Quantum Physics · Physics 2024-07-23 Bodo Rosenhahn , Christoph Hirche

Network monitoring generates massive volumes of IP flow records, posing significant challenges for storage and analysis. This paper presents a novel deep learning-based approach to compressing these records using autoencoders, enabling…

Networking and Internet Architecture · Computer Science 2025-02-03 Adrian Pekar

Network management and security is currently one of the most vibrant research areas, among which, research on detecting and identifying anomalies has attracted a lot of interest. Researchers are still struggling to find an effective and…

Networking and Internet Architecture · Computer Science 2010-07-09 Huy Nguyen , Tam Van Nguyen , Dong Il Kim , Deokjai Choi

In modern world the importance of cybersecurity of various systems is increasing from year to year. The number of information security events generated by information security tools grows up with the development of the IT infrastructure. At…

Cryptography and Security · Computer Science 2025-06-17 Evgeniy Eremin

Unsupervised anomaly detection and localization is crucial to the practical application when collecting and labeling sufficient anomaly data is infeasible. Most existing representation-based approaches extract normal image features with a…

Computer Vision and Pattern Recognition · Computer Science 2021-11-17 Jiawei Yu , Ye Zheng , Xiang Wang , Wei Li , Yushuang Wu , Rui Zhao , Liwei Wu

The ability to identify applications based on the network data they generate could be a valuable tool for cyber defense. We report on a machine learning technique capable of using netflow-like features to predict the application that…

Cryptography and Security · Computer Science 2021-09-09 Justin Allen , David Knapp , Kristine Monteith

This work proposes a real-time anomaly detection scheme that leverages the multi-step ahead prediction capabilities of encoder-decoder (ED) deep learning models with recurrent units. Specifically, an encoder-decoder is used to model…

Machine Learning · Computer Science 2023-09-08 Sadananda Behera , Tania Panayiotou , Georgios Ellinas

With the widespread adoption of cloud services, especially the extensive deployment of plenty of Web applications, it is important and challenging to detect anomalies from the packet payload. For example, the anomalies in the packet payload…

Signal Processing · Electrical Eng. & Systems 2021-05-20 Jiaxin Liu , Xucheng Song , Yingjie Zhou , Xi Peng , Yanru Zhang , Pei Liu , Dapeng Wu

Cyber-attacks continue to grow, both in terms of volume and sophistication. This is aided by an increase in available computational power, expanding attack surfaces, and advancements in the human understanding of how to make attacks…

Cryptography and Security · Computer Science 2021-03-09 Hanan Hindy , Robert Atkinson , Christos Tachtatzis , Ethan Bayne , Miroslav Bures , Xavier Bellekens

Normalizing flows are prominent deep generative models that provide tractable probability distributions and efficient density estimation. However, they are well known to fail while detecting Out-of-Distribution (OOD) inputs as they directly…

Machine Learning · Computer Science 2021-11-17 Nishant Kumar , Pia Hanfeld , Michael Hecht , Michael Bussmann , Stefan Gumhold , Nico Hoffmann