Rasd: Semantic Shift Detection and Adaptation for Network Intrusion Detection

被引:0
|
作者
Alotaibi, Fahad [1 ]
Maffeis, Sergio [1 ]
机构
[1] Imperial Coll London, Dept Comp, London, England
关键词
Distribution Shift; Shift Detection and Adaptation; Network Security; Intrusion Detection;
D O I
10.1007/978-3-031-65175-5_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection Systems (NIDSs) based on Deep Neural Network have demonstrated impressive performance in multi-class, closed-world settings, where training and test data follow the same distribution. However, when deployed in real networks, these systems have a limited ability to detect novel attacks which do not belong to already known classes. In this work, we aim to tackle semantic shift, that is the emergence of unknown classes, by proposing a two-phase approach to detect new classes and integrate them into the classification model, while minimising the need for human intervention. While contrastive learning is a promising techniques to tackle semantic shift, it has high computational cost and it is sensitive to imbalanced data. We propose a novel contrastive learning approach based on synthetic centroids which has low computational cost and is robust to class imbalance, making it suitable for application to NIDS. To integrate the shifted samples in the existing model, we also design a novel adaptation method that combines manual labeling and pseudo-labeling to reduce labeling costs. We evaluate our system, Rasd, on two NIDS datasets, finding it excels in both detection and adaptation. For example Rasd improves on the nearest detection baseline F1-score by 6.83% for IDS 2017 and 19.21% for IDS 2018.
引用
收藏
页码:16 / 30
页数:15
相关论文
共 50 条
  • [1] Joint Semantic Transfer Network for IoT Intrusion Detection
    Wu, Jiashu
    Wang, Yang
    Xie, Binhui
    Li, Shuang
    Dai, Hao
    Ye, Kejiang
    Xu, Chengzhong
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (04) : 3368 - 3383
  • [2] Network intrusion detection based on shift-or circuit
    Roan, Huang-Chun
    Hwang, Wen-Jyi
    Huang, Wei-Jhih
    Lo, Chia-Tien Dan
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2008, 24 (04) : 1229 - 1239
  • [3] Semantic Shift Detection in Semantic Web
    Ren, Ke
    Huang, Zhixing
    Zhao, Anping
    Qiu, Yuhui
    2009 FIFTH INTERNATIONAL CONFERENCE ON SEMANTICS, KNOWLEDGE AND GRID (SKG 2009), 2009, : 416 - 417
  • [4] NETWORK INTRUSION DETECTION
    MUKHERJEE, B
    HEBERLEIN, LT
    LEVITT, KN
    IEEE NETWORK, 1994, 8 (03): : 26 - 41
  • [5] Wireless Intrusion Detection: Not as easy as traditional network intrusion detection
    Tao, Zhiqi
    Ruighaver, A. B.
    TENCON 2005 - 2005 IEEE REGION 10 CONFERENCE, VOLS 1-5, 2006, : 2513 - +
  • [6] Shift-or circuit for efficient network intrusion detection pattern matching
    Roan, Huang-Chun
    Hwang, Wen-Jyi
    Lo, Chia-Tien Dan
    2006 INTERNATIONAL CONFERENCE ON FIELD PROGRAMMABLE LOGIC AND APPLICATIONS, PROCEEDINGS, 2006, : 785 - 790
  • [7] Heterogeneous network intrusion detection via domain adaptation in IoT environment
    Zhang, Jun
    Li, Yao
    Zhang, Litian
    INTERNET TECHNOLOGY LETTERS, 2025, 8 (01)
  • [8] Adaptation techniques for intrusion detection and intrusion response systems
    Ragsdale, DJ
    Carver, CA
    Humphries, JW
    Pooch, UW
    SMC 2000 CONFERENCE PROCEEDINGS: 2000 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOL 1-5, 2000, : 2344 - 2349
  • [9] Anomaly detection schemes in network intrusion detection
    Corvera, S
    Grau, JB
    Andina, D
    Soft Computing with Industrial Applications, Vol 17, 2004, 17 : 309 - 313
  • [10] Abnormal traffic detection for network intrusion detection
    Heo, YJ
    Ryu, KW
    SAM '04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, 2004, : 387 - 390