提出特征扰动评分,识别难被篡改的网络流量特征以防御攻击。
A Novel Perturb-ability Score to Mitigate Evasion Adversarial Attacks on Flow-Based ML-NIDS
- 基于流量语义设计扰动评分,量化特征被恶意修改的难易程度。
- 屏蔽高评分特征后,检测率下降小于5%,但抗攻击能力显著提升。
- 适合关注网络入侵检测系统安全性的研究人员和工程师。
随着网络安全威胁演进,保护基于流的机器学习网络入侵检测系统(ML-NIDS)免受逃避型对抗攻击至关重要。本文提出特征扰动性概念,并引入新型扰动评分(Perturb-ability Score, PS),用于量化攻击者在问题空间中操纵网络流量特征的难易程度。该评分可识别因网络流量字段语义约束与领域特异性关联而结构上难以被篡改的特征。攻击者若试图修改这些特征,很可能破坏攻击功能、导致流量无效,或两者兼有。我们提出并验证了基于PS的防御策略:PS引导的特征选择与掩码机制,显著提升了流式ML-NIDS的鲁棒性。在多个主流模型与公开数据集上的实验表明,剔除或掩码高扰动性特征(高PS特征)后,检测性能维持稳定(性能下降<5%),同时大幅降低对逃避型对抗攻击的脆弱性。结果证实PS能有效识别易受问题空间扰动影响的特征。该方法利用问题空间的领域约束,构建轻量级通用防御机制,适用于流式ML-NIDS的抗逃避攻击防护。
原文摘要 · Abstract (English)
As network security threats evolve, safeguarding flow-based Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) from evasion adversarial attacks is crucial. This paper introduces the notion of feature perturb-ability and presents a novel Perturb-ability Score (PS), which quantifies how susceptible NIDS features are to manipulation in the problem-space by an attacker. PS thereby identifies features structurally resistant to evasion attacks in flow-based ML-NIDS due to the semantics of network traffic fields, as these features are constrained by domain-specific limitations and correlations. Consequently, attempts to manipulate such features would likely either compromise the attack's malicious functionality, render the traffic invalid for processing, or potentially both outcomes simultaneously. We introduce and demonstrate the effectiveness of our PS-enabled defenses, PS-guided feature selection and PS-guided feature masking, in enhancing flow-based NIDS resilience. Experimental results across various ML-based NIDS models and public datasets show that discarding or masking highly manipulatable features (high-PS features) can maintain solid detection performance while significantly reducing vulnerability to evasion adversarial attacks. Our findings confirm that PS effectively identifies flow-based NIDS features susceptible to problem-space perturbations. This novel approach leverages problem-space NIDS domain constraints as lightweight universal defense mechanisms against evasion adversarial attacks targeting flow-based ML-NIDS.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。