The escalating threat and impact of network-based attacks necessitate innovative intrusion detection systems. Machine learning has shown promise, with recent strides in quantum machine learning offering new avenues. However, the potential of quantum computing is tempered by challenges in current noisy intermediate-scale quantum era machines. In this article, we explore quantum neural networks (QNNs) for intrusion detection, optimizing their performance within current quantum computing limitations. Our approach includes efficient classical feature encoding, QNN classifier selection, and performance tuning leveraging current quantum computational power. This study culminates in an optimized multilayered QNN architecture for network intrusion detection. A small version of the proposed architecture was implemented on IonQ's Aria-1 quantum computer, achieving a notable 0.86 F1 score using the NF-UNSW-NB15 dataset. In addition, we introduce a novel metric, certainty factor, laying the foundation for future integration of uncertainty measures in quantum classification outputs. Moreover, this factor is used to predict the noise susceptibility of our quantum binary classification system.
Network traffic has been shown to be self-similar across a wide range of protocols, including Ethernet, Wi-Fi, and cellular traffic. However, the composition of the Internet has grown since these initial findings to include machine-to-machine (M2M) traffic, which behaves differently than the human-generated traffic previously analyzed. In this changing landscape, it has yet to be shown if the M2M traffic generated in industrial control systems (ICS) is self-similar. This paper investigates the self-similarity of M2M traffic using network traffic from three publicly available datasets. We find that the M2M traffic was not self-similar for two of the datasets, while the third showed a low degree of self-similarity. Furthermore, we demonstrate using physical data that the Hurst parameter can be used as a metric to observe changes in the system configuration of an ICS and to detect anomalous activity in the network.
Research has shown network traffic to be self-similar for various connection protocols, and 5G traffic has been modeled as self-similar based on the assumption that it adheres to these previously established traffic behaviors. However, to support the continued use of known self-similar traffic models in 5G technology, it is necessary to demonstrate self-similarity within 5G network traffic in a physical environment and investigate the factors that affect it. This research uses an AMARI Callbox Mini to develop a 5G Standalone (SA) network testbed to generate and analyze 5G network traffic. Using the Rescaled Range estimation method, the Hurst parameter of this traffic is measured to determine its degree of self-similarity. Our analysis demonstrates that traffic within a 5G standalone network is statistically self-similar, and the degree to which it displays this property increases with traffic load. Furthermore, this research shows that self-similarity varies dependent on the medium in which the traffic is collected and analyzed.
Network traffic was first determined to be self-similar through the analysis of core Ethernet traces and has since been shown to demonstrate this characteristic under various connection protocols. However, the variation in self-similarity of network traffic due to changing connection protocol (e.g. WiFi to Ethernet) has not been explored, nor has it been shown how self-similarity behaves as data from different sources aggregates physically from the edge to a network’s core. We establish that the increased variability inherent to wireless communications increases self-similarity when measured at the edge due to the conditions of the transmission medium and the protocols in place for wired and wireless connections. Furthermore, once aggregated on a wired link, the stability of wired protocols is shown to have the most significant impact on the estimated self-similarity, and the core traffic is less bursty.
This work describes a novel application of robust estimation to the detection of volumetric anomalies in computer network traffic. The proposed tests are based on sample location and dispersion and derived from relatively unknown Zero Order Statistics. The proposed tests are non-parametric and suitable for a range of applications to heavy-tailed data analysis outside of network traffic. The performance of these tests is examined using two different real-world denial-of-service attacks contained in actual high-volume backbone traffic. The proposed tests outperform traditional metrics such as mean and variance due to the presence of heavy tails in the network traffic, a frequent characteristic of traffic in actual networks. Monte Carlo analysis is used to quantify the performance gains and show an improvement in accuracy between 7 and 11% at very low false alarm rates. The proposed tests also demonstrate equivalent or superior performance to the median, a common robust statistic. Constructive timing of key system processes is used to demonstrate near real-time performance. Three- and six- second data windows containing between 750 and 1200 elements can be processed in less than one second using commodity hardware running unoptimized code. These timing results imply scalability to a variety of networks and commercial applications. Scalability prospects are further enhanced by demonstrating resilient detection performance at attack volumes between 25 and 100 percent of baseline rates in both real and generated traffic.
5G New Radio (NR) represents a shift in mobile telephony whereby the network architecture runs containerized software on commodity hardware. In preparation, numerous 4G software stacks have been developed to test the containerization of core network functions and the interfaces with radio access network (RAN) protocols. In this work one such stack, developed by the OpenAirInterface Software Alliance (OSA), is used to create a low-cost, simplified mobile network. Commercial off-the-shelf (COTS) user equipment (UE) is then connected to the network to demonstrate how a major buffer overflow vulnerability present in certain Global Navigation Satellite System (GNSS) chipsets can be leveraged to enable a spoofed network attack. Finally, the theoretical attack method is extended to 5G NR networks.
A simplified cybersecurity threat matrix may provide a unifying way to define the security risk posed by current and future generations of mobile telephony.
As digital trust has declined, services purporting to provide privacy and anonymity have become increasingly popular in today's online environment. While there are several examples of these types of applications, blockchain-based services like Bitcoin and Ethereum have emerged as a potential answer to some of these privacy concerns. Unfortunately, many of the same features that facilitate that privacy and anonymity can also be leveraged by nefarious actors to transmit and store information covertly. These features can also be used by government and military organizations for communications purposes. In this paper, we present a generic information hiding model incorporating anonymity that builds on existing classical steganographic models like the Prisoners' Problem. We then analyze our model with regards to blockchain protocols and present a novel blockchain-based address embedding scheme. Finally, we implement our scheme using the Ethereum platform.
Computer network traffic features do not always conform with traditional Poisson and Gaussian models. For instance, the α-stable distribution frequently provides a more accurate model for high-volume network traffic. To more accurately characterize SYN traffic, we propose a novel mixture based on measurements from our local network. The proposed Lévy-impulse model utilizes an impulse function to account for a high zero-probability and the Lévy distribution to account for the heavy-tailed features of host-sent SYN packets. We develop a probability density function of the Lévy-impulse model for various window lengths and apply it to real-world data. We then utilize maximum likelihood estimation and real-world network traffic to demonstrate the accuracy of the model. The proposed model demonstrates higher accuracy than traditional models like Poisson or Gaussian for the examined traffic case. Additionally, the relative invariance of the model’s fit to the size of the traffic window allows for scalable applications. Ultimately, this Lévy-impulse mixture can serve as a model for normal network traffic to develop improved computer worm detection techniques.
Cyber security is a multi-functionary area of practice; effective solutions are difficult because of the diverse range of expertise required and the impact of fallible humans.The impact and number of successful attacks grows every year even while cyber security spending grows at a double-digit annual rate.To fundamentally improve the state of cyber security, research must consider cross-disciplinary techniques and investigate novel paths; incremental progress is unlikely to fundamentally improve the state of the practice.
Heavy-tailed models of computer network traffic have been shown to more accurately reflect the actual traffic distributions of many traffic features than methods based on exponential distributions. The power-law tail inherent to alpha-stable distributions better accommodates network traffic properties such as impulsiveness, self-similarity, and long-range dependence, enabling more precise models and more accurate network anomaly detection. Beginning from individual traffic processes, this work presents two explanatory mathematical methods for device aggregation which lead to either Gaussian or alpha-stable traffic distributions. The first method, based on the generalized central limit theorem, shows how self-similarity originates from an impulsive-noise-based representation of individual processes. A second method based on renewal theory supports the predictions of the first method and explains aggregation, in some networks, to Gaussian fractional Brownian motion. We develop working models to empirically validate the proposed approaches which can forecast the resulting aggregation based on the characteristics of the input devices.
Cyber Systems and associated analytics will enable a future where secure, cognitive technologies anticipate longand short-term information needs, perceptively coordinate and adapt distributed sensors, and deliver timely and accurate information and recommendations to humans and machines. Effective designs will require machine-to-human, human-to-machine, and machine-to-machine collaboration. This minitrack invites original, technical research in the subject area.
This work presents two explanatory mathematical models explaining how network traffic features that display Gaus-sian tendencies in single devices and small networks aggregate to alpha-stable processes in larger networks. The first model shows how self-similarity originates from an impulsive-noise-based representation of individual processes. A second model uses renewal processes to justify impulsive process aggregation to alpha-stable or Gaussian end states and permits estimating network traffic alpha-stable rates of convergence. We develop a model based on this first method to empirically validate this aggregation approach.
Cyber Systems and associated analytics will enable a future where secure, cognitive technologies anticipate long-and short-term information needs, perceptively coordinate and adapt distributed sensors, and deliver timely and accurate information and recommendations to humans and machines.Effective designs will require machine-to-human, human-to-machine, and machine-to-machine collaboration.This minitrack invites original, technical research in the subject area.
Computer worms pose a major threat to computer and communication networks due to the rapid speed at which they propagate. Biologically based epidemic models have been widely used to analyze the propagation of worms in computer networks. For an air-gapped network with an insider threat, we propose a modified Susceptible-Exposed-Infected-Quarantined-Vaccinated (SEIQV) model called the Susceptible-Exposed-Infected-Quarantined-Patched (SEIQP) model. We describe the assumptions that apply to this model, define a set of differential equations that characterize the system dynamics, and solve for the basic reproduction number. We then simulate and analyze the parameters controlled by the insider threat to determine where resources should be allocated to attain different objectives and results.
The stable distribution has been shown to more accurately model some aspects of network traffic than alternative distributions. In this work, we quantitatively examine aspects of the modeling performance of the stable distribution as envisioned in a statistical network cyber event detection system. We examine the flexibility and robustness of the stable distribution, extending previous work by comparing the performance of the stable distribution against alternatives using three different, public network traffic data sets with a mix of traffic rates and cyber events. After showing the stable distribution to be the overall most accurate for the examined scenarios, we use the Hellinger metric to investigate the ability of the stable distribution to reduce modeling error when using small data windows and counting periods. For the selected case and metric, the stable model is compared to a Gaussian model and is shown to produce the best overall fit as well as the best (or at worst, equivalent) fit for all counting periods. Additionally, the best stable fit occurs at a counting period that is five times shorter than the best Gaussian case. These results imply that the stable distribution can provide a more robust and accurate model than Gaussian-based alternatives in statistical network anomaly detection implementations while also facilitating faster system detection and response.
Aspects of network traffic, among other impulsive time series, can be more accurately represented using the family of stable distributions. Simple, closed form solutions for stable distributions do not exist, other than special cases. Mixtures of one of these special cases, the Levy (or Pearson V) distribution, can be used to provide a closed-form approximation of positive a-stable (PaS) distributions. We show that for a specific network traffic trace, accurate closed-form approximations of a PaS time series can be obtained with only four mixture components. Additionally, we provide an algorithm for creating Levy Mixture Approximations (LMAs) and demonstrate that non-linear methods can improve model accuracy while constraining the number of components and computational cost. This approach provides a computationally-tractable, accurate model for non-Gaussian, positive (or negative) time series such as network traffic. This model is in a form that is less costly for follow-on processing and detection, potentially facilitating real-time applications.