An intrusion detection model to detect zero-day attacks in unseen data using machine learning

被引:0
|
作者
Dai, Zhen [1 ]
Por, Lip Yee [1 ]
Chen, Yen-Lin [2 ]
Yang, Jing [1 ]
Ku, Chin Soon [3 ]
Alizadehsani, Roohallah [4 ]
Plawiak, Pawel [5 ,6 ]
机构
[1] Univ Malaya, Fac Comp Sci & Informat Technol, Dept Comp Syst & Technol, Kuala Lumpur, Malaysia
[2] Natl Taipei Univ Technol, Dept Comp Sci & Informat Engn, Taipei, Taiwan
[3] Univ Tunku Abdul Rahman, Dept Comp Sci, Kampar, Malaysia
[4] Deakin Univ, Inst Intelligent Syst Res & Innovat IISRI, Waurn Ponds, Australia
[5] Cracow Univ Technol, Fac Comp Sci & Telecommun, Dept Comp Sci, Krakow, Poland
[6] Polish Acad Sci, Inst Theoret & Appl Informat, Gliwice, Poland
来源
PLOS ONE | 2024年 / 19卷 / 09期
关键词
D O I
10.1371/journal.pone.0308469
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
In an era marked by pervasive digital connectivity, cybersecurity concerns have escalated. The rapid evolution of technology has led to a spectrum of cyber threats, including sophisticated zero-day attacks. This research addresses the challenge of existing intrusion detection systems in identifying zero-day attacks using the CIC-MalMem-2022 dataset and autoencoders for anomaly detection. The trained autoencoder is integrated with XGBoost and Random Forest, resulting in the models XGBoost-AE and Random Forest-AE. The study demonstrates that incorporating an anomaly detector into traditional models significantly enhances performance. The Random Forest-AE model achieved 100% accuracy, precision, recall, F1 score, and Matthews Correlation Coefficient (MCC), outperforming the methods proposed by Balasubramanian et al., Khan, Mezina et al., Smith et al., and Dener et al. When tested on unseen data, the Random Forest-AE model achieved an accuracy of 99.9892%, precision of 100%, recall of 99.9803%, F1 score of 99.9901%, and MCC of 99.8313%. This research highlights the effectiveness of the proposed model in maintaining high accuracy even with previously unseen data.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] Detecting Zero-Day Intrusion Attacks Using Semi-Supervised Machine Learning Approaches
    Mbona, Innocent
    Eloff, Jan H. P.
    [J]. IEEE ACCESS, 2022, 10 : 69822 - 69838
  • [2] An adaptable deep learning-based intrusion detection system to zero-day attacks
    Soltani, Mahdi
    Ousat, Behzad
    Siavoshani, Mahdi Jafari
    Jahangir, Amir Hossein
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 76
  • [3] Federated Incremental Learning based Evolvable Intrusion Detection System for Zero-Day Attacks
    Jin, Dong
    Chen, Shuangwu
    He, Huasen
    Jiang, Xiaofeng
    Cheng, Siyu
    Yang, Jian
    [J]. IEEE NETWORK, 2023, 37 (01): : 125 - 132
  • [4] A Brief Review of Unsupervised Learning Algorithms for Zero-Day Attacks in Intrusion Detection Systems
    Oluwadare, Sunkanmi
    ElSayed, Zag
    Adekoya, Oluwaseun
    [J]. 2024 IEEE 3RD INTERNATIONAL CONFERENCE ON COMPUTING AND MACHINE INTELLIGENCE, ICMI 2024, 2024,
  • [5] Zero-Day Malware Classification and Detection Using Machine Learning
    Kumar J.
    Rajendran B.
    Sudarsan S.D.
    [J]. SN Computer Science, 5 (1)
  • [6] Signature Based Intrusion Detection for Zero-Day Attacks: (Not) A Closed Chapter?
    Holm, Hannes
    [J]. 2014 47TH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2014, : 4895 - 4904
  • [7] Detection of Zero-day Attacks on IoT
    Reardon, Shay
    Hssayeni, Murtadha D.
    Mahgoub, Imadeldin
    [J]. 2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [8] Unsupervised Algorithms to Detect Zero-Day Attacks: Strategy and Application
    Zoppi, Tommaso
    Ceccarelli, Andrea
    Bondavalli, Andrea
    [J]. IEEE ACCESS, 2021, 9 : 90603 - 90615
  • [9] From zero-shot machine learning to zero-day attack detection
    Mohanad Sarhan
    Siamak Layeghy
    Marcus Gallagher
    Marius Portmann
    [J]. International Journal of Information Security, 2023, 22 : 947 - 959
  • [10] From zero-shot machine learning to zero-day attack detection
    Sarhan, Mohanad
    Layeghy, Siamak
    Gallagher, Marcus
    Portmann, Marius
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (04) : 947 - 959