返回
Towards Model Generalization for Intrusion Detection: Unsupervised Machine Learning Techniques
DOI:10.1007/s10922-021-09615-7.png)
摘要
En 中文
Through the ongoing digitization of the world, the number of connected devices is continuously growing without any foreseen decline in the near future. In particular, these devices increasingly include critical systems such as power grids and medical institutions, possibly causing tremendous consequences in the case of a successful cybersecurity attack. A network intrusion detection system (NIDS) is one of the main components to detect ongoing attacks by differentiating normal from malicious traffic. Anomaly-based NIDS, more specifically unsupervised methods previously proved promising for their ability to detect known as well as zero-day attacks without the need for a labeled dataset. Despite decades of development by researchers, anomaly-based NIDS are only rarely employed in real-world applications, most possibly due to the lack of generalization power of the proposed models. This article first evaluates four unsupervised machine learning methods on two recent datasets and then defines their generalization strength using a novel inter-dataset evaluation strategy estimating their adaptability. Results show that all models can present high classification scores on an individual dataset but fail to directly transfer those to a second unseen but related dataset. Specifically, the accuracy dropped on average 25.63% in an inter-dataset setting compared to the conventional evaluation approach. This generalization challenge can be observed and tackled in future research with the help of the proposed evaluation strategy in this paper.
Keyword:
Intrusion detection
Network security
Cybersecurity
Unsupervised techniques
Generalization strength
Inter-dataset evaluation
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.9
论文数:
1.0K
被引数:
1.3K
机构
引用论文
Effective action of a scalar field in a curved spacetime with a small inhomogeneity具有小不均匀性的弯曲时空中标量场的有效作用量
From Intrusion Detection to Attacker Attribution: A Comprehensive Survey of Unsupervised Methods从入侵检测到攻击者归因: 无监督方法的综合考察
Survey on SDN based network intrusion detection system using machine learning approaches基于机器学习方法的SDN网络入侵检测系统综述
Deep-Full-Range: A Deep Learning Based Network Encrypted Traffic Classification and Intrusion Detection FrameworkDeep-Full-Range: 基于深度学习的网络加密流量分类和入侵检测框架
IEEE ACCESS
IF3.6
Analysis and assessment of ship collision accidents using Fault Tree and Multiple Correspondence Analysis基于故障树和多重对应分析的船舶碰撞事故分析与评估
A Flying Squirrel Search Optimization for MPPT Under Partial Shaded Photovoltaic System局部遮挡光伏系统MPPT的飞鼠搜索优化

