Go With the Flow: Clustering Dynamically-Defined NetFlow Features for Network Intrusion Detection with DYNIDS

被引:1
|
作者
Dias, Luis [1 ,2 ]
Valente, Simao [1 ,2 ]
Correia, Miguel [2 ]
机构
[1] Inst Univ Mil, Acad Mil, CINAMIL, Lisbon, Portugal
[2] Univ Lisbon, Inst Super Tecn, INESC ID, Lisbon, Portugal
关键词
network intrusion detection; clustering; feature engineering; security analytics; ANOMALY DETECTION;
D O I
10.1109/nca51143.2020.9306732
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The paper presents DYNIDS, a network intrusion detection approach that flags malicious activity without previous knowledge about attacks or training data. DYNIDS dynamically defines and extracts features from network data, and uses clustering algorithms to aggregate hosts with similar behavior. All previous clustering-based network intrusion detection approaches use a static set of features, restricting their ability to detect certain attacks. Instead, we use a set of features defined dynamically, at runtime, avoiding that restriction without falling into the curse of dimensionality, something that we believe is essential for the adoption of this kind of approaches. We evaluated DYNIDS experimentally with an evaluation and a real-world dataset, obtaining better F-Score than alternative solutions.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Network Intrusion Detection in Software-Defined Network using Deep and Machine Learning
    Mhamdi, Lotfi
    Hamdi, Hedi
    Mahmood, Mahmood A.
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 2692 - 2697
  • [42] Differentiating network conversation flow for intrusion detection and diagnostics
    McEachen, JC
    Zachary, JM
    Ettlich, DW
    2004 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOL 4, PROCEEDINGS, 2004, : 473 - 476
  • [43] Explainable Boosting Machines for Network Intrusion Detection with Features Reduction
    El-Mihoub, Tarek A.
    Nolle, Lars
    Stahl, Frederic
    ARTIFICIAL INTELLIGENCE XXXIX, AI 2022, 2022, 13652 : 280 - 294
  • [44] A Framework for Efficient Network Anomaly Intrusion Detection with Features Selection
    Anwer, Hebatallah Mostafa
    Farouk, Mohamed
    Abdel-Hamid, Ayman
    2018 9TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS (ICICS), 2018, : 157 - 162
  • [45] An Improved Kernel Clustering Algorithm Used in Computer Network Intrusion Detection
    He, Di
    Chen, Xin
    Zou, Danping
    Pei, Ling
    Jiang, Lingge
    2018 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2018,
  • [46] A Membership Function for Feature Clustering Based Network Intrusion and Anomaly Detection
    Nagaraja, Arun
    Kumar, T. Satish
    ICEMIS'18: PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE ON ENGINEERING AND MIS, 2018,
  • [47] Entropy clustering-based granular classifiers for network intrusion detection
    Hui Liu
    Gang Hao
    Bin Xing
    EURASIP Journal on Wireless Communications and Networking, 2020
  • [48] A Hybrid Clustering Approach for Network Intrusion Detection Using Cobweb and FFT
    Panda, Mrutyunjaya
    Patra, Manas
    JOURNAL OF INTELLIGENT SYSTEMS, 2009, 18 (03) : 229 - 245
  • [49] A Hybrid FCM Clustering-Neural Network Model for Intrusion Detection
    Jawhar, Muna M. T.
    Mehrotra, Monica
    MEMS, NANO AND SMART SYSTEMS, PTS 1-6, 2012, 403-408 : 3519 - +
  • [50] Network intrusion detection method based on ant colony optimization clustering
    College of Computer Science and Engineering, Chongqing University, Chongqing 400044, China
    不详
    不详
    Harbin Gongcheng Daxue Xuebao, 2006, SUPPL. (510-513):