Rasd: Semantic Shift Detection and Adaptation for Network Intrusion Detection

被引:0
|
作者
Alotaibi, Fahad [1 ]
Maffeis, Sergio [1 ]
机构
[1] Imperial Coll London, Dept Comp, London, England
关键词
Distribution Shift; Shift Detection and Adaptation; Network Security; Intrusion Detection;
D O I
10.1007/978-3-031-65175-5_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection Systems (NIDSs) based on Deep Neural Network have demonstrated impressive performance in multi-class, closed-world settings, where training and test data follow the same distribution. However, when deployed in real networks, these systems have a limited ability to detect novel attacks which do not belong to already known classes. In this work, we aim to tackle semantic shift, that is the emergence of unknown classes, by proposing a two-phase approach to detect new classes and integrate them into the classification model, while minimising the need for human intervention. While contrastive learning is a promising techniques to tackle semantic shift, it has high computational cost and it is sensitive to imbalanced data. We propose a novel contrastive learning approach based on synthetic centroids which has low computational cost and is robust to class imbalance, making it suitable for application to NIDS. To integrate the shifted samples in the existing model, we also design a novel adaptation method that combines manual labeling and pseudo-labeling to reduce labeling costs. We evaluate our system, Rasd, on two NIDS datasets, finding it excels in both detection and adaptation. For example Rasd improves on the nearest detection baseline F1-score by 6.83% for IDS 2017 and 19.21% for IDS 2018.
引用
收藏
页码:16 / 30
页数:15
相关论文
共 50 条
  • [31] Improving the Speed of the Network Intrusion Detection
    Sadeghi, Zahra
    Bahrami, Asadollah Shah
    2013 5TH CONFERENCE ON INFORMATION AND KNOWLEDGE TECHNOLOGY (IKT), 2013, : 88 - 91
  • [32] Integrating intrusion detection and network management
    Qin, XH
    Lee, W
    Lewis, L
    Cabrera, JBD
    NOMS 2002: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM: MANAGEMENT SOLUTIONS FOR THE NEW COMMUNICATIONS WORLD, 2002, : 329 - 344
  • [33] Analysis of Autoencoders for Network Intrusion Detection
    Song, Youngrok
    Hyun, Sangwon
    Cheong, Yun-Gyung
    SENSORS, 2021, 21 (13)
  • [34] SoK - Network Intrusion Detection on FPGA
    Le Jeune, Laurens
    Sateesan, Arish
    Rabbani, Md Masoom
    Goedeme, Toon
    Vliegen, Jo
    Mentens, Nele
    SECURITY, PRIVACY, AND APPLIED CRYPTOGRAPHY ENGINEERING, SPACE 2021, 2022, 13162 : 242 - 261
  • [35] A framework for Network Intrusion Detection in Cloud
    Prwez, Md Tarique
    Chatterjee, Kakali
    2016 IEEE 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (IACC), 2016, : 512 - 516
  • [36] Adaptive clustering for network intrusion detection
    Oldmeadow, J
    Ravinutala, S
    Leckie, C
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2004, 3056 : 255 - 259
  • [37] Enhanced Network Intrusion Detection System
    Kotecha, Ketan
    Verma, Raghav
    Rao, Prahalad, V
    Prasad, Priyanshu
    Mishra, Vipul Kumar
    Badal, Tapas
    Jain, Divyansh
    Garg, Deepak
    Sharma, Shakti
    SENSORS, 2021, 21 (23)
  • [38] Applying neural network to intrusion detection
    Zhou, Rigui
    2007 INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE & TECHNOLOGY, PROCEEDINGS, 2007, : 273 - 276
  • [39] Virtualization in Network Intrusion Detection Systems
    Akhlaq, Monis
    Alserhani, Faeiz
    Awan, Irfan U.
    Cullen, Andrea J.
    Mellor, John
    Mirchandani, Pravin
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2009 WORKSHOPS, 2009, 5872 : 6 - +
  • [40] Network Intrusion Detection in Encrypted Traffic
    Papadogiannaki, Eva
    Tsirantonakis, Giorgos
    Ioannidis, Sotiris
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,