ESVI-GaMM: A fast network intrusion detection approach based on the Bayesian gamma mixture model

被引:0
|
作者
He, Wenda [1 ]
Cai, Xiangrui [1 ]
Lai, Yuping [2 ]
Yuan, Xiaojie [1 ]
机构
[1] Nankai Univ, Coll Comp Sci, TKLNDST, Tianjin, Peoples R China
[2] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing, Peoples R China
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
Bayesian inference; Gamma mixture model; Extended stochastic variational inference; Network intrusion detection; ANOMALY DETECTION; DETECTION SYSTEM; CLASSIFIER; MACHINE;
D O I
10.1016/j.ins.2024.121001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the application of networks permeates various aspects of daily life, maintaining network security has become a crucial challenge. A network intrusion detection system (NIDS) functions as a critical technique for securing cyberspace and has gained considerable attention. Although researchers have made significant progress in developing NIDSs, challenges still exist in high -speed networks with overwhelming network traffic. Existing methods largely focus on improving model detection accuracy and often overlook speed and computational efficiency. This oversight renders most current methods impractical for real -world high -speed network scenarios. To address this issue, we propose an innovative and efficient network intrusion detection algorithm, namely, the Bayesian gamma mixture model (GaMM) classifier. With the recently proposed extended stochastic variational inference (ESVI) framework, we introduce lower-bound approximations to the evidence lower bound (ELBO), namely, the original variational object function. An analytically tractable Bayesian estimation algorithm for a GaMM is derived through stochastic optimization of the obtained lower bound and we validate its performance and computational efficiency on three publicly available datasets (CICMalmem2022, OPCUA, and CICIDS2018). The experimental results indicate that the proposed classifier not only achieves a detection performance comparable to that of other benchmark models but also significantly reduces both the training and detection times.
引用
下载
收藏
页数:13
相关论文
共 50 条
  • [31] An immunity-based model for network intrusion detection
    Zhang, YC
    Que, XR
    Wang, WD
    Cheng, SD
    2001 INTERNATIONAL CONFERENCES ON INFO-TECH AND INFO-NET PROCEEDINGS, CONFERENCE A-G: INFO-TECH & INFO-NET: A KEY TO BETTER LIFE, 2001, : E24 - E29
  • [32] SVM-based network intrusion detection model
    Zhang, Kun
    Cao, Hong-Xin
    Liu, Feng-Yu
    Li, Qian-Mu
    Nanjing Li Gong Daxue Xuebao/Journal of Nanjing University of Science and Technology, 2007, 31 (04): : 403 - 408
  • [33] A Network Intrusion Detection Algorithm Based on FSA Model
    Wu, Fei
    Wu, Donghui
    Yang, Yingen
    PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTING TECHNOLOGY, 2016, 60 : 615 - 621
  • [34] A model of immunity-based network intrusion detection
    Sun, ZX
    Mao, ZX
    Gong, J
    Xu, HX
    Wang, RC
    CHINESE JOURNAL OF ELECTRONICS, 2005, 14 (03): : 417 - 420
  • [35] An Intrusion Detection Model Based on Deep Belief Network
    Qu, Feng
    Zhang, Jitao
    Shao, Zetian
    Qi, Shuzhuang
    PROCEEDINGS OF 2017 VI INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2017), 2017, : 97 - 101
  • [36] An efficient intrusion detection model based on fast inductive learning
    Yang, Wu
    Wan, Wei
    Guo, Lin
    Zhang, Le-Jun
    PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 3249 - 3254
  • [37] A model for intrusion detection system using hidden Markov and variational Bayesian model for IoT based wireless sensor network
    Kalnoor G.
    Gowrishankar S.
    International Journal of Information Technology, 2022, 14 (4) : 2021 - 2033
  • [38] A novel network intrusion detection algorithm based on Fast Fourier Transformation
    Liu, Weiyou
    Liu, Xu
    Di, Xiaoqiang
    Qi, Hui
    2019 1ST INTERNATIONAL CONFERENCE ON INDUSTRIAL ARTIFICIAL INTELLIGENCE (IAI 2019), 2019,
  • [39] Anomaly Network Intrusion Detection Based on Improved Self Adaptive Bayesian Algorithm
    Farid, Dewan Md.
    Rahman, Mohammad Zahidur
    JOURNAL OF COMPUTERS, 2010, 5 (01) : 23 - 31
  • [40] Bayesian Classifier and Snort based Network Intrusion Detection System in Cloud Computing
    Modi, Chirag N.
    Patel, Dhiren R.
    Patel, Avi
    Muttukrishnan, Rajarajan
    2012 THIRD INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION & NETWORKING TECHNOLOGIES (ICCCNT), 2012,