FS-IDS: A framework for intrusion detection based on few-shot learning

被引:21
|
作者
Yang, Jingcheng [1 ]
Li, Hongwei [1 ]
Shao, Shuo [1 ]
Zou, Futai [1 ]
Wu, Yue [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Elect Informat & Elect Engn, Shanghai, Peoples R China
基金
美国国家科学基金会; 国家重点研发计划;
关键词
Network security; Intrusion detection system; Few -shot learning; Feature fusion; CNN; Deep learning; NEURAL-NETWORKS;
D O I
10.1016/j.cose.2022.102899
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A B S T R A C T Due to the high dependency of traditional intrusion detection method on a fully-labeled large dataset, existing works can hardly be applied in real-world scenarios, especially facing zero-day attacks. In this paper we present a novel intrusion detection framework called "FS-IDS", including flow data encoding method, feature fusion mechanism and architecture of intrusion detection system based on few-shot learning. We utilize task generator to split the dataset into separate tasks and train model in an episodic way, hoping model to learn general knowledge rather than those specific to a single class. The extraction module and distance metric module are responsible for learning and determining whether the traffic data are benign or not. We conduct three sets of experiments on "FS-IDS", i.e., comparison study, abla-tion study and multiclass study. Comparison study firstly determines that the best measure metric for discrimination is Euclidean distance. Based on the optimal implementation, "FS-IDS" achieves compa-rable performance with existing works by using much fewer malicious samples. Ablation study sets two base models to explore how proposed encoding method and feature fusion mechanism improve detection capacity. Both the image representation and feature fusion achieve more than 2% improvement in accu-racy and recall. Finally, to test whether "FS-IDS" can perform well under real-world scenario or not, we design network traffic containing various attacks to simulate complex malicious network environment. Experimental results show that "FS-IDS" maintains more than 90% detection accuracy and recall under the worst circumstances, which composes of various seen or unseen attacks with only a few malicious samples available.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] FS-IDS: A Novel Few-Shot Learning Based Intrusion Detection System for SCADA Networks
    Ouyang, Yuankai
    Li, Beibei
    Kong, Qinglei
    Song, Han
    Li, Tao
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021), 2021,
  • [2] A Method of Few-Shot Network Intrusion Detection Based on Meta-Learning Framework
    Xu, Congyuan
    Shen, Jizhong
    Du, Xin
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 3540 - 3552
  • [3] An Intrusion Detection Method Using Few-Shot Learning
    Yu, Yingwei
    Bian, Naizheng
    IEEE ACCESS, 2020, 8 (08): : 49730 - 49740
  • [4] A few-shot learning based method for industrial internet intrusion detection
    Wang, Yahui
    Zhang, Zhiyong
    Zhao, Kejing
    Wang, Peng
    Wu, Ruirui
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (05) : 3241 - 3252
  • [5] PTN-IDS: Prototypical Network Solution for the Few-shot Detection in Intrusion Detection Systems
    Niknami, Nadia
    Mahzoon, Vahid
    Wu, Jie
    2024 IEEE 49TH CONFERENCE ON LOCAL COMPUTER NETWORKS, LCN 2024, 2024,
  • [6] A Survey of Few-Shot Learning: An Effective Method for Intrusion Detection
    Duan, Ruixue
    Li, Dan
    Tong, Qiang
    Yang, Tao
    Liu, Xiaotong
    Liu, Xiulei
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [7] A Hybrid Few-Shot Learning Based Intrusion Detection Method for Internet of Vehicles
    Zhao, Yixuan
    Cui, Jianming
    Liu, Ming
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT II, 2024, 14488 : 207 - 220
  • [8] A few-shot network intrusion detection method based on mutual centralized learning
    Congyuan Xu
    Fan Zhang
    Ziqi Yang
    Zhihao Zhou
    Yuqi Zheng
    Scientific Reports, 15 (1)
  • [9] A Few-shot Deep Learning Approach for Improved Intrusion Detection
    Chowdhury, Md Moin Uddin
    Hammond, Frederick
    Konowicz, Glenn
    Xin, Chunsheng
    Wu, Hongyi
    Li, Jiang
    2017 IEEE 8TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (UEMCON), 2017, : 456 - +
  • [10] Intrusion Detection Using Few-shot Learning Based on Triplet Graph Convolutional Network
    Wang, Yue
    Jiang, Yiming
    Lan, Julong
    JOURNAL OF WEB ENGINEERING, 2021, 20 (05): : 1527 - 1552