File Download

There are no files associated with this item.

  • Find it @ UNIST can give you direct access to the published full text of this article. (UNISTARs only)
Related Researcher

박새롬

Park, Saerom
Read More

Views & Downloads

Detailed Information

Cited time in webofscience Cited time in scopus
Metadata Downloads

HACOE: hierarchical attack classification with outlier exposure

Author(s)
Kim, SeongminPark, SaeromLim, Yeon-sup
Issued Date
2025-09
DOI
10.1007/s10586-025-05396-9
URI
https://scholarworks.unist.ac.kr/handle/201301/87986
Citation
CLUSTER COMPUTING, v.28, no.674, pp.674
Abstract
Traffic classification is critical for network security, particularly in identifying and mitigating malicious network attacks. With the rapid progress of network technologies, the emergence of new types of network applications (unseen applications) can pose significant challenges to traffic classification methods. Additionally, the increasing prevalence of encrypted traffic due to concerns about privacy and data security further complicates the detection of unprecedented and unseen cyberattacks. Although machine learning-based approaches have demonstrated enhanced accuracy in handling complicated network patterns, identifying unseen attacks primarily relies on unsupervised methods or limited observations of new attack examples. We introduce a novel approach that combines hierarchical traffic classification with outlier exposure techniques (HACOE) to address these challenges. This approach enables the identification of unseen attacks without the need for prior exposure to specific attack data. By enhancing the calibration of neural network confidence through outlier exposure, HACOE distinguishes unseen attacks as a separate class while identifying benign and known attack types. Our experimental results show the effectiveness of HACOE in detecting unseen attacks; HACOE identifies up to 50% of unseen attacks while incorrectly classifying only 4-18% of benign instances as unseen. In addition, under the same setting for the existing zero-day detection baselines, HACOE demonstrates better or comparable performance while providing accurate classification results for known attacks.
Publisher
SPRINGER
ISSN
1386-7857
Keyword (Author)
Network anomaly detectionNetwork traffic classificationOut-of-distribution detectionOutlier exposure
Keyword
ENCRYPTED TRAFFIC CLASSIFICATIONINTRUSION

qrcode

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.