arrow
Return

A Deep Learning Ensemble Approach to Detecting Unknown Network Attacks

delete2022-06-01
delete18
PRE
AI
R
Rasheed Ahmad *
I
Izzat Alsmadi
W
Wasim A. Al-Hamdani
L
Lo’ai Tawalbeh
DOI:10.1016/j.jisa.2022.103196delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The majority of the intrusion detection solutions proposed using machine learning and deep learning approaches are based on known attack classes only. Comprehensive threat detection systems should consider both known and unknown attacks. Rapidly changing network environment and the advanced tools and techniques used by adversaries to launch new sophisticated attacks highlight a growing need to build intrusion detection systems that are more realistic, diverse, and robust to detect known and unknown attacks. We employed deep-learning models in our experiments to detect unknown threats, never introduced before to the model. This paper also studied the bias issues in connection with unknown threats detection. Many recent research studies based on conventional machine learning may report biased results and restricted training due to relying only on a single dataset; thus, there are existing threats that the model is unaware of, although the model may have high accuracy (in the known territories). This study presents a realistic IDS approach in which a deep learning classifiers' ensemble is trained on four benchmark IDS datasets for testing the unknown attack instances. Specifically, the model has no prior knowledge of some labels and traffic patterns in those experiments. The architecture proposed builds a deep learning ensemble using classifiers well-known to process and produce good results for sequential data. Our empirical results indicate that the proposed ensemble model can detect a range of unknown attacks with reasonable performance measures and a practical approach towards building a comprehensive IDS solution.
Keywords:
Intrusion Detection System (IDS)
Deep learning
Unknown attacks
Internet of Things (IoT)
Benchmark network datasets

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
1.9K
Citations:
4.9K

Organization

University of the Cumberlands cover
University of the Cumberlands
Scholars:
94
Papers: 70
Citations: 39
T
Texas A&M University System
Scholars:
4.4W
Papers: 4.0W
Citations: 4.0K