Analysis of Continual Learning Models for Intrusion Detection System

被引:9
|
作者
Prasath, Sai [1 ]
Sethi, Kamalakanta [2 ]
Mohanty, Dinesh [1 ]
Bera, Padmalochan [1 ]
Samantaray, Subhransu Ranjan [1 ]
机构
[1] IIT Bhubaneswar, Kansapada 752050, India
[2] Indian Inst Informat Technol Sricity, Sri City 517646, India
关键词
Intrusion detection systems; catastrophic forgetting; covariate shift; continual learning;
D O I
10.1109/ACCESS.2022.3222715
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep Learning based Intrusion Detection Systems (IDSs) have received significant attention from the research community for their capability to handle modern-day security systems in large-scale networks. Despite their considerable improvement in performance over machine learning-based techniques and conventional statistical models, deep neural networks (DNN) suffer from catastrophic forgetting: the model forgets previously learned information when trained on newer data points. This vulnerability is specifically exaggerated in large scale systems due to the frequent changes in network architecture and behaviours, which leads to changes in data distribution and the introduction of zero-day attacks; this phenomenon is termed as covariate shift. Due to these constant changes in the data distribution, the DNN models will not be able to consistently perform at high accuracy and low false positive rate (FPR) rates without regular updates. However, before we update the DNN models, it is essential to understand the magnitude and nature of the drift in the data distribution. In this paper, to analyze the drift in data distribution, we propose an eight-stage statistics and machine learning guided implementation framework that objectively studies and quantifies the changes. Further, to handle the changes in data distribution, most IDS solutions collect the network packets and store them to retrain the DNN models periodically, but when the network's size and complexity increase, those tasks become expensive. To efficiently solve this problem, we explore the potential of continual learning models to incrementally learn new data patterns while also retaining their previous knowledge. We perform an experimental and analytical study of advanced intrusion detection systems using three major continual learning approaches: learning without forgetting, experience replay, and dark experience replay on the NSL-KDD and the CICIDS 2017 dataset. Through extensive experimentation, we show that our continual learning models achieve improved accuracy and lower FPR rates when compared to the state-of-the-art works while also being able to incrementally learn newer data patterns. Finally, we highlight the drawbacks of traditional statistical and non-gradient based machine learning approaches in handling the covariate shift problem.
引用
收藏
页码:121444 / 121464
页数:21
相关论文
共 50 条
  • [1] A Multi-Class Intrusion Detection System Based on Continual Learning
    Oikonomou, Chrysoula
    Iliopoulos, Ilias
    Ioannidis, Dimosthenis
    Tzovaras, Dimitrios
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 86 - 91
  • [2] Hierarchical Multiclass Continual Learning for Network Intrusion Detection
    Talpini, Jacopo
    Sartori, Fabio
    Savi, Marco
    [J]. 2024 IEEE 10TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT 2024, 2024, : 263 - 267
  • [3] Analysis and Evaluation of Hybrid Intrusion Detection System Models
    Bello, Farid Lawan
    Ravulakollu, Kiran
    Amrita
    [J]. 2015 INTERNATIONAL CONFERENCE ON COMPUTERS, COMMUNICATIONS, AND SYSTEMS (ICCCS), 2015, : 93 - 97
  • [4] Intrusion detection system models
    Sin, LN
    Chuen, LM
    [J]. SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 359 - 364
  • [5] Toward an Online Continual Learning Architecture for Intrusion Detection of Video Surveillance
    Kwon, Beom
    Kim, Taewan
    [J]. IEEE ACCESS, 2022, 10 : 89732 - 89744
  • [6] A Sensitivity Analysis of Poisoning and Evasion Attacks in Network Intrusion Detection System Machine Learning Models
    Talty, Kevin
    Stockdale, John
    Bastian, Nathaniel D.
    [J]. 2021 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2021), 2021,
  • [7] Comparative Analysis of Machine Learning Models in Computer Network Intrusion Detection
    Osa, Edosa
    Oghenevbaire, Ogodo Efevberha
    [J]. 2022 IEEE NIGERIA 4TH INTERNATIONAL CONFERENCE ON DISRUPTIVE TECHNOLOGIES FOR SUSTAINABLE DEVELOPMENT (IEEE NIGERCON), 2022, : 648 - 652
  • [8] PERFORMANCE ANALYSIS OF MACHINE LEARNING TECHNIQUES FOR INTRUSION DETECTION SYSTEM
    Jadhav, Abhijit D.
    Pellakuri, Vidyullatha
    [J]. 2019 5TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, CONTROL AND AUTOMATION (ICCUBEA), 2019,
  • [9] EFFICIENT INTRUSION DETECTION SYSTEM MODELS
    Adsule, Urmila
    Pachghare, V. K.
    Kulkarni, Parag
    [J]. ICCNT 2009: PROCEEDINGS OF THE 2009 INTERNATIONAL CONFERENCE ON COMPUTER AND NETWORK TECHNOLOGY, 2010, : 199 - +
  • [10] Performance evaluation of learning models for intrusion detection system using feature selection
    Baijnath Kaushik
    Reya Sharma
    Kulwant Dhama
    Akshma Chadha
    Surbhi Sharma
    [J]. Journal of Computer Virology and Hacking Techniques, 2023, 19 : 529 - 548