2024 IEEE INTERNATIONAL WORKSHOP ON INFORMATION FORENSICS AND SECURITY, WIFS 2024(2024)
Univ Calif Santa Barbara
被引用0|浏览10
摘要
The escalating threats posed by cyber-attacks, particularly zero-day attacks, are projected to push the global annual cost of cybercrime to $10.5 trillion in 2025, with an anticipated 33 billion accounts breached [1]. Detecting these zero-day attacks, which exploit unknown vulnerabilities, is critical. This paper introduces the Graph-based Unknown Attack Recognition and Detection (GUARD) system, which combines autoencoders and graph theory to detect zero-day threats. GUARD translates latent representations and reconstruction errors from autoencoders into graphs, with edges weighted by similarity. Our novel technique, Hierarchical Quartet Loss, builds on the established triplet loss by using four elements and a hierarchical structure to enhance graph modularity by distinguishing both attacks and attack families. By analyzing patterns such as reconstruction error and cosine similarity, GUARD identifies unknown samples that deviate significantly from known patterns. Additionally, GUARD can discern multiple subclasses within the unknown dataset and represents them in a hierarchical family tree, offering a comprehensive visualization of network behaviors. Initial validation shows that GUARD improves zero-day attack detection precision and provides valuable insights into emerging threat characteristics and categorization.