Hybrid Explainable Intrusion Detection System: Global vs. Local Approach

被引:0
|
作者
Tanuwidjaja, Harry Chandra [1 ]
Takahashi, Takeshi [1 ]
Lin, Tsung-Nan [2 ]
Lee, Boyi [3 ]
Ban, Tao [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Tokyo, Japan
[2] Natl Taiwan Univ, Taipei, Taiwan
[3] Natl Appl Res Labs, Taipei, Taiwan
关键词
IDS; explanation; XAI; X-IDS; local interpretable model-agnostic explanations; Shapley additive explanation;
D O I
10.1145/3605772.3624004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDSs) play a major role in detecting suspicious activities and alerting users of potential malicious adversaries. Security operators investigate these alerts and attempt to mitigate the risks and damage. Many IDS-related studies have focused on improving detection accuracy and reducing false positives; however, the operators need to understand the rationale behind IDS engines issuing an alert. In contrast to conventional rule-based engines, machine-learning-based engines use a detection mechanism that is like a black box, i.e., it is not designed to indicate a rationale. In this paper, we introduce an explainable IDS (X-IDS) that copes with the well-used XAI techniques to ensure that the system can explain the decisions. To this end, we used local interpretable model-agnostic explanations and Shapley additive explanations, and we evaluated their differing characteristics. We proposed our explanation framework that consists of the variable importance plot, individual value plot, and partial dependence plot. Furthermore, we conclude by discussing future issues regarding better explainable IDS.
引用
收藏
页码:37 / 42
页数:6
相关论文
共 50 条
  • [41] Local vs. Global Optimization for Optical Line System Control in Disaggregated Networks
    Borraccini, Giacomo
    D'Amico, Andrea
    Straullu, Stefano
    Aquilino, Francesco
    Piciaccia, Stefano
    Tanzi, Alberto
    Galimberti, Gabriele
    Curri, Vittorio
    [J]. 2023 INTERNATIONAL CONFERENCE ON OPTICAL NETWORK DESIGN AND MODELING, ONDM, 2023,
  • [42] Local and Global Feature Based Explainable Feature Envy Detection
    Yin, Xin
    Shi, Chongyang
    Zhao, Shuxin
    [J]. 2021 IEEE 45TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2021), 2021, : 942 - 951
  • [43] Creating an Explainable Intrusion Detection System Using Self Organizing Maps
    Ables, Jesse
    Kirby, Thomas
    Anderson, William
    Mittal, Sudip
    Rahimi, Shahram
    Banicescu, Ioana
    Seale, Maria
    [J]. 2022 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2022, : 404 - 412
  • [44] Conservative vs. Optimistic Parallelization of Stateful Network Intrusion Detection
    Schuff, Derek L.
    Choe, Yung Ryn
    Pai, Vijay S.
    [J]. PROCEEDINGS OF THE 2007 ACM SIGPLAN SYMPOSIUM ON PRINCIPLES AND PRACTICE OF PARALLEL PROGRAMMING PPOPP'07, 2007, : 138 - 139
  • [45] Conservative vs. optimistic parallelization of stateful network intrusion detection
    Schuff, Derek. L.
    Choe, Yung Ryn
    Pai, Vijay S.
    [J]. ISPASS 2008: IEEE INTERNATIONAL SYMPOSIUM ON PERFORMANCE ANALYSIS OF SYSTEMS AND SOFTWARE, 2008, : 32 - 43
  • [46] Hybrid Triodetection Approach: A Framework for Intrusion Detection
    Sree, M. Mahithaa
    Saranya, M.
    Shyry, S. Prayla
    [J]. INTERNATIONAL CONFERENCE ON INTELLIGENT DATA COMMUNICATION TECHNOLOGIES AND INTERNET OF THINGS, ICICI 2018, 2019, 26 : 1032 - 1038
  • [47] A hybrid approach to the profile creation and intrusion detection
    Marin, J
    Ragsdale, D
    Surdu, J
    [J]. DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL I, PROCEEDINGS, 2001, : 69 - 76
  • [48] A Hybrid Classifier Approach for Network Intrusion Detection
    Arivardhini, S.
    Alamelu, L. Muthu
    Deepika, S.
    [J]. 2020 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2020, : 824 - 827
  • [49] A Hybrid Intelligent Approach for Network Intrusion Detection
    Panda, Mrutyunjaya
    Abraham, Ajith
    Patra, Manas Ranjan
    [J]. INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY AND SYSTEM DESIGN 2011, 2012, 30 : 1 - 9
  • [50] A hybrid CNN-LSTM approach for intelligent cyber intrusion detection system
    Bamber, Sukhvinder Singh
    Katkuri, Aditya Vardhan Reddy
    Sharma, Shubham
    Angurala, Mohit
    [J]. Computers and Security, 2025, 148