Synthetic attack data generation model applying generative adversarial network for intrusion detection

被引:33
|
作者
Kumar, Vikash [1 ,2 ]
Sinha, Ditipriya [2 ]
机构
[1] Siksha O Anusandhan Deemed be Univ, Dept Comp Sci & Engn, Bhubaneswar, India
[2] Natl Inst Technol Patna, Dept Comp Sci & Engn, Patna, Bihar, India
关键词
Intrusion detection system; Cyber-attack; Generative adversarial networks; Data synthetization; Data imbalance; DEEP LEARNING APPROACH; INTERNET;
D O I
10.1016/j.cose.2022.103054
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detecting a large number of attack classes accurately applying machine learning (ML) and deep learn-ing (DL) techniques depends on the number of representative samples available for each attack class. In most cases, the data samples are highly imbalanced that results in a biased intrusion detection model towards the majority classes. Under-sampling, over-sampling and SMOTE are some techniques among the solutions that turn the imbalanced dataset to balanced one. These techniques have not had much impact on the improvement of detection accuracy. To deal with this problem, this paper proposes a Wasser-stein Conditional Generative Adversarial Network (WCGAN) combined with an XGBoost Classifier. Gra-dient penalty along with the WCGAN is used for stable learning of the model. The proposed model is evaluated with some other GAN models (i.e., standard/vanilla GAN, Conditional GAN) which shows the significance of applying WCGAN in this paper. The loss on generated and real data shows a similar pat-tern and is lower for the Wasserstein variants of GAN compared to the other variants of the GAN model. The performance is benchmarked on three datasets NSL-KDD, UNSW-NB15 and BoT-IoT. The comparison of performance metrics before and after using the proposed framework with XGBoost classifier shows im-provement in terms of higher precision, recall and F-1 score. However, comparatively less improvement is observed in FAR compared to other classifiers such as Random Forest (RF), Decision Tree (DT), Support Vector Machine (SVM). The proposed work is also compared with a recent similar technique called DGM, which uses conditional GAN along with different ML classification models. The performance of the pro-posed model outperforms DGM. The proposed model creates a significant footprint (or, attack signatures) to tackle with the problem of data-imbalance during the design of the Intrusion Detection System (IDS).(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Intrusion Detection System in Wireless Sensor Network Using Conditional Generative Adversarial Network
    Tanya Sood
    Satyartha Prakash
    Sandeep Sharma
    Abhilash Singh
    Hemant Choubey
    Wireless Personal Communications, 2022, 126 : 911 - 931
  • [42] Intrusion Detection System in Wireless Sensor Network Using Conditional Generative Adversarial Network
    Sood, Tanya
    Prakash, Satyartha
    Sharma, Sandeep
    Singh, Abhilash
    Choubey, Hemant
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 126 (01) : 911 - 931
  • [43] SCAN-GAN: Generative Adversarial Network Based Synthetic Data Generation Technique for Controller Area Network
    Chougule A.
    Agrawal K.
    Chamola V.
    IEEE Internet of Things Magazine, 2023, 6 (03): : 126 - 130
  • [44] SURFGenerator: Generative Adversarial Network Modeling for Synthetic Flooding Video Generation
    Lamczyk, Stephen
    Ampofo, Kwame
    Salashour, Behrouz
    Cetin, Mecit
    Iftekharuddin, Khan M.
    2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [45] Intrusion Detection Method Based on Complementary Adversarial Generation Network
    Li, Lixiang
    Liu, Yuxuan
    Peng, Haipeng
    ADVANCES IN SWARM INTELLIGENCE, ICSI 2023, PT II, 2023, 13969 : 260 - 271
  • [46] Presentation Attack Face Image Generation Based on a Deep Generative Adversarial Network
    Dat Tien Nguyen
    Tuyen Danh Pham
    Batchuluun, Ganbayar
    Noh, Kyoung Jun
    Park, Kang Ryoung
    SENSORS, 2020, 20 (07) : 1 - 25
  • [47] Synthetic flow-based cryptomining attack generation through Generative Adversarial Networks
    Alberto Mozo
    Ángel González-Prieto
    Antonio Pastor
    Sandra Gómez-Canaval
    Edgar Talavera
    Scientific Reports, 12
  • [48] Synthetic flow-based cryptomining attack generation through Generative Adversarial Networks
    Mozo, Alberto
    Gonzalez-Prieto, Angel
    Pastor, Antonio
    Gomez-Canaval, Sandra
    Talavera, Edgar
    SCIENTIFIC REPORTS, 2022, 12 (01)
  • [49] Improving synthetic media generation and detection using generative adversarial networks
    Zia, Rabbia
    Rehman, Mariam
    Hussain, Afzaal
    Nazeer, Shahbaz
    Anjum, Maria
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [50] Conditional Generative Adversarial Network for Intrusion Detection System Based on Deep Learning
    Huang, Zhen
    Xiang, Yong
    2024 16TH INTERNATIONAL CONFERENCE ON COMPUTER AND AUTOMATION ENGINEERING, ICCAE 2024, 2024, : 237 - 241