Hybrid Convolutional Neural Network-Gated Recurrent Unit-Attention and Autoencoder Framework for Zero-Day Network Attack Detection: A Computational Approach with Experimental Evaluation on CICIDS2017
Résumé
Zero-day attacks-exploiting unknown vulnerabilities before patches exist-pose a critical threat to modern network infrastructure that signature-based intrusion detection systems cannot address.This paper proposes a hybrid computational framework combining a Convolutional Neural Network (CNN)-Gated Recurrent Unit (GRU)-Attention classifier with a skip-connection convolutional autoencoder (AE) for simultaneous known-attack classification and zero-day anomaly detection.The framework introduces three key computational contributions: (1) deterministic reshaping of 64 Random Forest-selected network flow features into 8 × 8 spatial images, enabling end-to-end CNN processing without feature engineering; (2) a strict Score-based Label Separation and Ordering (SLSO) data partition enforcing complete information isolation between training, validation, and zero-day evaluation sets; and(3) an OR-fusion hybrid decision rule combining anomaly score and reconstruction error signals.Experimental evaluation on Canadian Institute for Cybersecurity Intrusion Detection System (CICIDS)2017 demonstrates 97.48% zero-day detection rate (Z-DR) (95% confidence interval (CI) [97.1%, 97.9%]) at 4.2% false positive rate (FPR) and Area Under the Receiver Operating Characteristic curve (AUROC) of 0.956 across three held-out zero-day attack families-substantially outperforming all classical baselines (best: Stochastic Gradient Descent-optimized One-Class Support Vector Machine (SGD-OCSVM) at 85.45%).SHapley Additive exPlanations (SHAP) explainability analysis reveals mechanistic complementarity: the CNN captures temporal flow signatures while the AE contributes 1,012 exclusive detections via backward inter-arrival time anomalies.The system operates at 14,201 samples/second on Graphics Processing Unit (GPU), satisfying real-time deployment requirements.These results demonstrate that hybrid supervised-unsupervised fusion with rigorous experimental methodology substantially advances zero-day detection capability for computational network security systems.
Citer ce document
Accès au document
Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter
Voir l'article sur le site de la revueAuteur(s)
Statistiques
Consultations : 1
Téléchargements : 0