On the Evaluation of Sequential Machine Learning for Network Intrusion Detection

被引:11
|
作者
Corsini, Andrea [1 ]
Yang, Shanchieh Jay [2 ]
Apruzzese, Giovanni [3 ]
机构
[1] Univ Modena & Reggio Emilia, Modena, Italy
[2] Rochester Inst Technol, Rochester, NY 14623 USA
[3] Univ Liechtenstein, Vaduz, Liechtenstein
关键词
Long Short Term Memory; Machine Learning; Network Intrusion Detection; Cybersecurity; Network Flows; Deep Learning; BOTNET;
D O I
10.1145/3465481.3470065
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent advances in deep learning renewed the research interests in machine learning for Network Intrusion Detection Systems (NIDS). Specifically, attention has been given to sequential learning models, due to their ability to extract the temporal characteristics of network traffic flows (NetFlows), and use them for NIDS tasks. However, the applications of these sequential models often consist of transferring and adapting methodologies directly from other fields, without an in-depth investigation on how to leverage the specific circumstances of cybersecurity scenarios; moreover, there is a lack of comprehensive studies on sequential models that rely on NetFlow data, which presents significant advantages over traditional full packet captures. We tackle this problem in this paper. We propose a detailed methodology to extract temporal sequences of NetFlows that denote patterns of malicious activities. Then, we apply this methodology to compare the efficacy of sequential learning models against traditional static learning models. In particular, we perform a fair comparison of a 'sequential' Long Short-Term Memory (LSTM) against a 'static' Feedforward Neural Networks (FNN) in distinct environments represented by two well-known datasets for NIDS: the CICIDS2017 and the CTU13. Our results highlight that LSTM achieves comparable performance to FNN in the CICIDS2017 with over 99.5% F1-score; while obtaining superior performance in the CTU13, with 95.7% F1-score against 91.5%. This paper thus paves the way to future applications of sequential learning models for NIDS.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Network Intrusion Detection on Apache Spark with Machine Learning Algorithms
    Kurt, Elif Merve
    Becerikli, Yasar
    ENGINEERING APPLICATIONS OF NEURAL NETWORKS, EANN 2018, 2018, 893 : 130 - 141
  • [22] Supervised Machine Learning Techniques for Efficient Network Intrusion Detection
    Aboueata, Nada
    Alrasbi, Sara
    Erbad, Aiman
    Kassler, Andreas
    Bhamare, Deval
    2019 28TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2019,
  • [23] Research on Network Intrusion Detection Technology Based on Machine Learning
    Wu, Fei
    Li, Ting
    Wu, Zhen
    Wu, ShuLin
    Xiao, ChuanQi
    INTERNATIONAL JOURNAL OF WIRELESS INFORMATION NETWORKS, 2021, 28 (03) : 262 - 275
  • [24] Intrusion Detection on the In-Vehicle Network Using Machine Learning
    Sharmin, Shaila
    Mansor, Hafizah
    2021 3RD INTERNATIONAL CYBER RESILIENCE CONFERENCE (CRC), 2021, : 26 - 31
  • [25] Advancing Network Intrusion Detection Systems with Machine Learning Techniques
    Benmalek, Mourad
    Haouam, Kamel-Dine
    ADVANCES IN ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING, 2024, 4 (03): : 2575 - 2592
  • [26] Adversarial machine learning for network intrusion detection: A comparative study
    Jmila, Houda
    Ibn Khedher, Mohamed
    COMPUTER NETWORKS, 2022, 214
  • [27] A dependable hybrid machine learning model for network intrusion detection
    Talukder, Md. Alamin
    Hasan, Khondokar Fida
    Islam, Md. Manowarul
    Uddin, Md. Ashraf
    Akhter, Arnisha
    Abu Yousuf, Mohammand
    Alharbi, Fares
    Moni, Mohammad Ali
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 72
  • [28] Investigating Network Intrusion Detection Datasets Using Machine Learning
    Amaizu, Gabriel Chukwunonso
    Nwakanma, Cosmas Ifeanyi
    Lee, Jae-Min
    Kim, Dong-Seong
    11TH INTERNATIONAL CONFERENCE ON ICT CONVERGENCE: DATA, NETWORK, AND AI IN THE AGE OF UNTACT (ICTC 2020), 2020, : 1325 - 1328
  • [29] Machine Learning for Network Intrusion Detection-A Comparative Study
    Al Lail, Mustafa
    Garcia, Alejandro
    Olivo, Saul
    FUTURE INTERNET, 2023, 15 (07):
  • [30] SoK: Pragmatic Assessment of Machine Learning for Network Intrusion Detection
    Apruzzese, Giovanni
    Laskov, Pavel
    Schneider, Johannes
    2023 IEEE 8TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, EUROS&P, 2023, : 592 - 614