Introducing Deep Learning Self-Adaptive Misuse Network Intrusion Detection Systems

被引:85
|
作者
Papamartzivanos, Dimitrios [1 ]
Gomez Marmol, Felix [2 ]
Kambourakis, Georgios [1 ]
机构
[1] Univ Aegean, Dept Informat & Commun Syst Engn, Samos 83200, Greece
[2] Univ Murcia, Dept Informat & Commun Engn, E-30100 Murcia, Spain
来源
IEEE ACCESS | 2019年 / 7卷
关键词
Adaptive intrusion detection systems; artificial neural networks; deep learning; information systems security; MAPE-K; sparse auto encoders; COMPREHENSIVE SURVEY; SWARM INTELLIGENCE;
D O I
10.1109/ACCESS.2019.2893871
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The intrusion detection systems (IDSs) are essential elements when it comes to the protection of an ICT infrastructure. A misuse IDS is a stable method that can achieve high attack detection rates (ADR) while keeping false alarm rates under acceptable levels. However, the misuse IDSs suffer from the lack of agility, as they are unqualified to adapt to new and "unknown'' environments. That is, such an IDS puts the security administrator into an intensive engineering task for keeping the IDS up-to-date every time it faces efficiency drops. Considering the extended size of modern networks and the complexity of big network traffic data, the problem exceeds the substantial limits of human managing capabilities. In this regard, we propose a novel methodology which combines the benefits of self-taught learning and MAPE-K frameworks to deliver a scalable, self-adaptive, and autonomous misuse IDS. Our methodology enables the misuse IDS to sustain high ADR, even if it is imposed on consecutive and drastic environmental changes. Through the utilization of deep-learning based methods, the IDS is able to grasp an attack's nature based on the generalized feature reconstructions stemming directly from the unknown environment and its unlabeled data. The experimental results reveal that our methodology can breathe new life into the IDS without the constant need for manually refreshing its training set. We evaluate our proposal under several classification metrics and demonstrate that the ADR of the IDS increases up to 73.37% in critical situations where a statically trained IDS is rendered totally ineffective.
引用
收藏
页码:13546 / 13560
页数:15
相关论文
共 50 条
  • [41] Deep Learning for Network Intrusion Detection in Virtual Networks
    Spiekermann, Daniel
    Eggendorfer, Tobias
    Keller, Joerg
    ELECTRONICS, 2024, 13 (18)
  • [42] Learning Classifier Systems for Adaptive Learning of Intrusion Detection System
    Lee, Chang Seok
    Cho, Sung Bae
    INTERNATIONAL JOINT CONFERENCE SOCO'17- CISIS'17-ICEUTE'17 PROCEEDINGS, 2018, 649 : 557 - 566
  • [43] Network Intrusion Detection System using Deep Learning
    Ashiku, Lirim
    Dagli, Cihan
    BIG DATA, IOT, AND AI FOR A SMARTER FUTURE, 2021, 185 : 239 - 247
  • [44] Online Reinforcement Learning for Self-adaptive Information Systems
    Palm, Alexander
    Metzger, Andreas
    Pohl, Klaus
    ADVANCED INFORMATION SYSTEMS ENGINEERING, CAISE 2020, 2020, 12127 : 169 - 184
  • [45] Self-adaptive routing based on learning classifier systems
    Huang, CY
    Sun, CT
    CEC2004: PROCEEDINGS OF THE 2004 CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1 AND 2, 2004, : 678 - 682
  • [46] Hierarchical deep reinforcement learning for self-adaptive economic dispatch
    Li, Mengshi
    Yang, Dongyan
    Xu, Yuhan
    Ji, Tianyao
    HELIYON, 2024, 10 (14)
  • [47] Self-adaptive logit balancing for deep neural network robustness: Defence and detection of adversarial attacks
    Wei, Jiefei
    Yao, Luyan
    Meng, Qinggang
    NEUROCOMPUTING, 2023, 531 : 180 - 194
  • [48] A dynamically self-adaptive intrusion detection architecture for mobile ad hoc networks
    Jin, X
    Zhang, YX
    Wei, YY
    ICCC2004: PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION VOL 1AND 2, 2004, : 484 - 487
  • [49] Deep Learning with a Self-Adaptive Threshold for OTFS Channel Estimation
    Zhang, Xiaoqi
    Yuan, Weijie
    Liu, Chang
    Liu, Fan
    Wen, Miaowen
    2022 INTERNATIONAL SYMPOSIUM ON WIRELESS COMMUNICATION SYSTEMS, ISWCS, 2022,
  • [50] A dynamically self-adaptive intrusion detection architecture for mobile ad hoc networks
    Jin, X
    Zhang, YX
    Wei, YY
    ICCC2004: PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION VOL 1AND 2, 2004, : 761 - 765