arXiv:2501.15563cs.LGcs.CR2025-01被引 14

提出针对网络流量的后门毒化工具,仅用1%数据即可让模型误判恶意流量。

PCAP-Backdoor: Backdoor Poisoning Generator for Network Traffic in CPS/IoT Environments

  • 设计新方法PCAP-Backdoor,从真实网络数据中注入触发器进行毒化
  • 仅需1%以下训练数据污染,就能使模型在含触发器时误判恶意流量
  • 现有防御手段难以检测此类后门,适合研究安全漏洞的学者参考

随着联网设备的快速扩展,其成为网络攻击的主要目标。为应对这些威胁,基于深度学习的数据驱动入侵检测系统(IDS)已成为识别和缓解攻击的强大工具。这类系统通过分析网络流量来发现异常模式和异常行为,以判断潜在的安全事件。然而,已有研究揭示深度学习模型易受后门攻击:攻击者可向模型中注入触发器,从而操纵其行为并导致对网络流量的误分类。本文探讨了在工业控制系统(CPS)与物联网(IoT)环境下的网络流量分析中,深度学习驱动的IDS系统对后门攻击的脆弱性。我们提出了 exttt{PCAP-Backdoor},一种新型技术,可对PCAP数据集实施后门毒化攻击。在真实世界中的CPS与IoT网络流量数据集上的实验表明,攻击者仅需污染整个训练数据集1%或更少,即可有效植入后门。此外,攻击者可在正常流量中嵌入触发器,使训练后的模型在遇到含触发器的恶意流量时发生误判。最后,我们强调即便使用现有的后门防御技术,也难以检测此类基于触发器的后门。

原文摘要 · Abstract (English)

The rapid expansion of connected devices has made them prime targets for cyberattacks. To address these threats, deep learning-based, data-driven intrusion detection systems (IDS) have emerged as powerful tools for detecting and mitigating such attacks. These IDSs analyze network traffic to identify unusual patterns and anomalies that may indicate potential security breaches. However, prior research has shown that deep learning models are vulnerable to backdoor attacks, where attackers inject triggers into the model to manipulate its behavior and cause misclassifications of network traffic. In this paper, we explore the susceptibility of deep learning-based IDS systems to backdoor attacks in the context of network traffic analysis. We introduce \texttt{PCAP-Backdoor}, a novel technique that facilitates backdoor poisoning attacks on PCAP datasets. Our experiments on real-world Cyber-Physical Systems (CPS) and Internet of Things (IoT) network traffic datasets demonstrate that attackers can effectively backdoor a model by poisoning as little as 1\% or less of the entire training dataset. Moreover, we show that an attacker can introduce a trigger into benign traffic during model training yet cause the backdoored model to misclassify malicious traffic when the trigger is present. Finally, we highlight the difficulty of detecting this trigger-based backdoor, even when using existing backdoor defense techniques.

后门攻击入侵检测网络流量

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。