Introducing Deep Learning Self-Adaptive Misuse Network Intrusion Detection Systems

被引:85
|
作者
Papamartzivanos, Dimitrios [1 ]
Gomez Marmol, Felix [2 ]
Kambourakis, Georgios [1 ]
机构
[1] Univ Aegean, Dept Informat & Commun Syst Engn, Samos 83200, Greece
[2] Univ Murcia, Dept Informat & Commun Engn, E-30100 Murcia, Spain
来源
IEEE ACCESS | 2019年 / 7卷
关键词
Adaptive intrusion detection systems; artificial neural networks; deep learning; information systems security; MAPE-K; sparse auto encoders; COMPREHENSIVE SURVEY; SWARM INTELLIGENCE;
D O I
10.1109/ACCESS.2019.2893871
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The intrusion detection systems (IDSs) are essential elements when it comes to the protection of an ICT infrastructure. A misuse IDS is a stable method that can achieve high attack detection rates (ADR) while keeping false alarm rates under acceptable levels. However, the misuse IDSs suffer from the lack of agility, as they are unqualified to adapt to new and "unknown'' environments. That is, such an IDS puts the security administrator into an intensive engineering task for keeping the IDS up-to-date every time it faces efficiency drops. Considering the extended size of modern networks and the complexity of big network traffic data, the problem exceeds the substantial limits of human managing capabilities. In this regard, we propose a novel methodology which combines the benefits of self-taught learning and MAPE-K frameworks to deliver a scalable, self-adaptive, and autonomous misuse IDS. Our methodology enables the misuse IDS to sustain high ADR, even if it is imposed on consecutive and drastic environmental changes. Through the utilization of deep-learning based methods, the IDS is able to grasp an attack's nature based on the generalized feature reconstructions stemming directly from the unknown environment and its unlabeled data. The experimental results reveal that our methodology can breathe new life into the IDS without the constant need for manually refreshing its training set. We evaluate our proposal under several classification metrics and demonstrate that the ADR of the IDS increases up to 73.37% in critical situations where a statically trained IDS is rendered totally ineffective.
引用
收藏
页码:13546 / 13560
页数:15
相关论文
共 50 条
  • [31] Divergence-Based Transferability Analysis for Self-Adaptive Smart Grid Intrusion Detection With Transfer Learning
    Liao, Pengyi
    Yan, Jun
    Sellier, Jean Michel
    Zhang, Yongxuan
    IEEE ACCESS, 2022, 10 : 68807 - 68818
  • [32] A Self-Adaptive Automatic Incident Detection System for Road Surveillance Based on Deep Learning
    Bartolome-Hornillos, Cesar
    San-Jose-Revuelta, Luis M.
    Aguiar-Perez, Javier M.
    Garcia-Serrada, Carlos
    Vara-Pazos, Eduardo
    Casaseca-de-la-Higuera, Pablo
    SENSORS, 2024, 24 (06)
  • [33] Deep Learning Network Intrusion Detection Based on Network Traffic
    Wang, Hanyang
    Zhou, Sirui
    Li, Honglei
    Hu, Juan
    Du, Xinran
    Zhou, Jinghui
    He, Yunlong
    Fu, Fa
    Yang, Houqun
    ARTIFICIAL INTELLIGENCE AND SECURITY, ICAIS 2022, PT III, 2022, 13340 : 194 - 207
  • [34] Deep Learning for Effective and Efficient Reduction of Large Adaptation Spaces in Self-adaptive Systems
    Weyns, Danny
    Gheibi, Omid
    Quin, Federico
    Van Der Donckt, Jeroen
    ACM TRANSACTIONS ON AUTONOMOUS AND ADAPTIVE SYSTEMS, 2022, 17 (1-2)
  • [35] Comprehensible and dependable self-learning self-adaptive systems
    Kloes, Verena
    Goethel, Thomas
    Glesner, Sabine
    JOURNAL OF SYSTEMS ARCHITECTURE, 2018, 85-86 : 28 - 42
  • [36] xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
    Wei, Feng
    Li, Hongda
    Zhao, Ziming
    Hu, Hongxin
    PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 4337 - 4354
  • [37] The Improved Training Algorithm of Deep Learning with Self-Adaptive Learning Rate
    Ongart, Sutit
    Jearanaitanakij, Kietikul
    Sangthong, Jirapat
    2018 18TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT), 2018, : 463 - 466
  • [38] A New Type of Self-adaptive Mechanism for Network Survivability Based on Intrusion Deception
    Li Nan
    Xia Chunhe
    Qi Jianzhong
    Wang Haiquan
    FGCN: PROCEEDINGS OF THE 2008 SECOND INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING, VOLS 1 AND 2, 2008, : 91 - 95
  • [39] Network intrusion detection methods based on deep learning
    Li X.
    Zhang S.
    Recent Patents on Engineering, 2021, 15 (04):
  • [40] Deep Learning Applications for Intrusion Detection in Network Traffic
    Getman, A. I.
    Rybolovlev, D. A.
    Nikolskaya, A. G.
    PROGRAMMING AND COMPUTER SOFTWARE, 2024, 50 (07) : 493 - 510