Improving synthetic network attack traffic generation

Abdirisaq Farah, Martin Nielsen, Emmanouil Vasilomanolakis

Research output: Chapter in Book/Report/Conference proceedingArticle in proceedingsResearchpeer-review

355 Downloads (Orbit)

Abstract

The increasing diversity and sophistication of cyber threats highlight the need for improved intrusion detection deployment. This need is nowadays often addressed via machine learning algorithms or other anomaly-based detection techniques. However, many of these proposals require realistic attack network datasets for training and evaluation. This is a problem that is often compensated with very old datasets (e.g., the KDD99) or others who are not public and therefore create reproducibility issues. To overcome such issues researchers proposed the creation of a dynamic toolkit that is able to generate attack traffic; the so-called Intrusion Detection Dataset Toolkit (ID2T). ID2T aims to generate synthetic, yet realistic attacks traces, for subsequent injection into benign background traffic. In this paper, we identify a number of limitations in ID2T that we subsequently resolve by proposing and implementing specific improvements. Moreover, we expand the tool to include more complex and modern attacks. For instance, we improve i) the background traffic manipulation modules, ii) the generation of realistic inter-arrival times between network packets, iii) the overall generated network packets in relation to the generation of context aware IP addresses, and iv) the usage of ephemeral ports and the creation of the synthetic payloads. Each improvement is followed by a respective implementation and an extensive evaluation.
Original languageEnglish
Title of host publicationProceedings of the 9th International Workshop on Traffic Measurements for Cybersecurity (WTMC 2024)
Number of pages9
PublisherIEEE
Publication date2024
ISBN (Print)979-8-3503-6732-4
ISBN (Electronic)979-8-3503-6729-4
DOIs
Publication statusPublished - 2024
Event9th International Workshop on Traffic Measurements for Cybersecurity
- Vienna, Austria
Duration: 8 Jul 20248 Jul 2024

Workshop

Workshop9th International Workshop on Traffic Measurements for Cybersecurity
Country/TerritoryAustria
CityVienna
Period08/07/202408/07/2024

Keywords

  • Network security
  • Intrusion detection
  • Synthetic attack generation
  • ID2T

Fingerprint

Dive into the research topics of 'Improving synthetic network attack traffic generation'. Together they form a unique fingerprint.

Cite this