On the Evaluation of Sequential Machine Learning for Network Intrusion Detection

被引:11
|
作者
Corsini, Andrea [1 ]
Yang, Shanchieh Jay [2 ]
Apruzzese, Giovanni [3 ]
机构
[1] Univ Modena & Reggio Emilia, Modena, Italy
[2] Rochester Inst Technol, Rochester, NY 14623 USA
[3] Univ Liechtenstein, Vaduz, Liechtenstein
关键词
Long Short Term Memory; Machine Learning; Network Intrusion Detection; Cybersecurity; Network Flows; Deep Learning; BOTNET;
D O I
10.1145/3465481.3470065
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent advances in deep learning renewed the research interests in machine learning for Network Intrusion Detection Systems (NIDS). Specifically, attention has been given to sequential learning models, due to their ability to extract the temporal characteristics of network traffic flows (NetFlows), and use them for NIDS tasks. However, the applications of these sequential models often consist of transferring and adapting methodologies directly from other fields, without an in-depth investigation on how to leverage the specific circumstances of cybersecurity scenarios; moreover, there is a lack of comprehensive studies on sequential models that rely on NetFlow data, which presents significant advantages over traditional full packet captures. We tackle this problem in this paper. We propose a detailed methodology to extract temporal sequences of NetFlows that denote patterns of malicious activities. Then, we apply this methodology to compare the efficacy of sequential learning models against traditional static learning models. In particular, we perform a fair comparison of a 'sequential' Long Short-Term Memory (LSTM) against a 'static' Feedforward Neural Networks (FNN) in distinct environments represented by two well-known datasets for NIDS: the CICIDS2017 and the CTU13. Our results highlight that LSTM achieves comparable performance to FNN in the CICIDS2017 with over 99.5% F1-score; while obtaining superior performance in the CTU13, with 95.7% F1-score against 91.5%. This paper thus paves the way to future applications of sequential learning models for NIDS.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Performance Evaluation of Supervised Machine Learning Algorithms for Intrusion Detection
    Belavagi, Manjula C.
    Muniyal, Balachandra
    TWELFTH INTERNATIONAL CONFERENCE ON COMMUNICATION NETWORKS, ICCN 2016 / TWELFTH INTERNATIONAL CONFERENCE ON DATA MINING AND WAREHOUSING, ICDMW 2016 / TWELFTH INTERNATIONAL CONFERENCE ON IMAGE AND SIGNAL PROCESSING, ICISP 2016, 2016, 89 : 117 - 123
  • [42] Evaluation of Machine Learning Algorithms for Intrusion Detection System in WSN
    Alsahli, Mohammed S.
    Almasri, Marwah M.
    Al-Akhras, Mousa
    Al-Issa, Abdulaziz I.
    Alawairdhi, Mohammed
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (05) : 617 - 626
  • [43] Comparative Evaluation of Network-Based Intrusion Detection: Deep Learning vs Traditional Machine Learning Approach
    Udurume, Miracle
    Shakhov, Vladimir
    Koo, Insoo
    2024 FIFTEENTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS, ICUFN 2024, 2024, : 520 - 525
  • [44] Comparison of Machine Learning and Deep Learning Models for Network Intrusion Detection Systems
    Thapa, Niraj
    Liu, Zhipeng
    Kc, Dukka B.
    Gokaraju, Balakrishna
    Roy, Kaushik
    FUTURE INTERNET, 2020, 12 (10) : 1 - 16
  • [45] Intrusion Detection of Imbalanced Network Traffic Based on Machine Learning and Deep Learning
    Liu, Lan
    Wang, Pengcheng
    Lin, Jun
    Liu, Langzhou
    IEEE Access, 2021, 9 : 7550 - 7563
  • [46] Intrusion Detection of Imbalanced Network Traffic Based on Machine Learning and Deep Learning
    Liu, Lan
    Wang, Pengcheng
    Lin, Jun
    Liu, Langzhou
    IEEE ACCESS, 2021, 9 : 7550 - 7563
  • [47] Synthetic Data Generation With Machine Learning for Network Intrusion Detection Systems
    Newlin, Marvin
    Reith, Mark
    DeYoung, Mark
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 785 - 789
  • [48] Comparative research on network intrusion detection methods based on machine learning
    Zhang, Chunying
    Jia, Donghao
    Wang, Liya
    Wang, Wenjie
    Liu, Fengchun
    Yang, Aimin
    COMPUTERS & SECURITY, 2022, 121
  • [49] An investigation and comparison of machine learning approaches for intrusion detection in IoMT network
    Adel Binbusayyis
    Haya Alaskar
    Thavavel Vaiyapuri
    M. Dinesh
    The Journal of Supercomputing, 2022, 78 : 17403 - 17422
  • [50] Network intrusion detection using oversampling technique and machine learning algorithms
    Ahmed, Hafiza Anisa
    Hameed, Anum
    Bawany, Narmeen Zakaria
    PEERJ COMPUTER SCIENCE, 2022, 8 : 1 - 19