LIO-IDS: Handling class imbalance using LSTM and improved one-vs-one technique in intrusion detection system

被引:51
|
作者
Gupta, Neha [1 ]
Jindal, Vinita [2 ]
Bedi, Punam [1 ]
机构
[1] Univ Delhi, Dept Comp Sci, Delhi, India
[2] Univ Delhi, Keshav Mahavidyalaya, Delhi, India
关键词
Cybersecurity; Network security; Class imbalance problem; Long short-term memory (LSTM); Improved one-vs-one technique (I-OVO); Network-based intrusion detection system (NIDS); SUPPORT VECTOR MACHINE; STRATEGY; SMOTE;
D O I
10.1016/j.comnet.2021.108076
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network-based Intrusion Detection Systems (NIDSs) are deployed in computer networks to identify intrusions. NIDSs analyse network traffic to detect malicious content generated from different types of cyber-attacks. Though NIDSs can classify frequent attacks correctly, their performance declines on infrequent network intrusions. This paper proposes LIO-IDS based on Long Short-Term Memory (LSTM) classifier and Improved Onevs-One technique for handling both frequent and infrequent network intrusions. LIO-IDS is a two-layer Anomalybased NIDS (A-NIDS) that detects different network intrusions with high Accuracy and low computational time. Layer 1 of LIO-IDS identifies intrusions from normal network traffic by using the LSTM classifier. Layer 2 uses ensemble algorithms to classify the detected intrusions into different attack classes. This paper also proposes an Improved One-vs-One (I-OVO) technique for performing multi-class classification at the second layer of the proposed LIO-IDS. In contrast to the traditional OVO technique, the proposed I-OVO technique uses only three classifiers to test each sample, thereby reducing the testing time significantly. Also, oversampling techniques have been used at Layer 2 to enhance the detection ability of the proposed LIO-IDS. The performance of the proposed system has been evaluated in terms of Accuracy, Recall, Precision, F1-score, Receiver Characteristics Operating (ROC) curve, Area Under ROC (AUC) values, training time and testing time for the NSL-KDD, CIDDS001, and CICIDS2017 datasets. The proposed LIO-IDS shows significant improvement in the results as compared to its counterparts. High attack detection rates and short computational times make the proposed LIO-IDS suitable to be deployed in the real-world for network-based intrusion detection.
引用
收藏
页数:19
相关论文
共 46 条
  • [21] Analysis of Intrusion Detection in Control System Communication Based on Outlier Detection with One-Class Classifiers
    Onoda, Takashi
    Kiuchi, Mai
    NEURAL INFORMATION PROCESSING, ICONIP 2012, PT V, 2012, 7667 : 275 - 282
  • [22] Improved Acknowledgement Intrusion Detection System in MANETs Using Hybrid Cryptographic Technique
    Patil, Trupti
    Joshi, Bharti
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON APPLIED AND THEORETICAL COMPUTING AND COMMUNICATION TECHNOLOGY (ICATCCT), 2015, : 636 - 641
  • [23] Intelligent One-Class Classifiers for the Development of an Intrusion Detection System: The MQTT Case Study
    Jove, Esteban
    Aveleira-Mata, Jose
    Alaiz-Moreton, Hector
    Casteleiro-Roca, Jose-Luis
    Marcos del Blanco, David Yeregui
    Zayas-Gato, Francisco
    Quintian, Hector
    Calvo-Rolle, Jose Luis
    ELECTRONICS, 2022, 11 (03)
  • [24] Intrusion Detection System Based on One-Class Support Vector Machine of COME Module
    Zhang L.
    Xie L.
    Jin L.-C.
    Wang Z.-L.
    Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology, 2019, 39 (09): : 978 - 986
  • [25] One-class IoT anomaly detection system using an improved interpolated SVDD autoencoder with adversarial
    Katbi, Abdulkarim
    Ksantini, Riadh
    DIGITAL SIGNAL PROCESSING, 2025, 162
  • [26] A Double-Layer Indemnity Enhancement Using LSTM and HASH Function Technique for Intrusion Detection System
    Ali, Abdullah Marish
    Alqurashi, Fahad
    Alsolami, Fawaz Jaber
    Qaiyum, Sana
    MATHEMATICS, 2023, 11 (18)
  • [27] Intrusion Detection System Based on One-Class Support Vector Machine and Gaussian Mixture Model
    Wang, Chao
    Sun, Yunxiao
    Lv, Sicai
    Wang, Chonghua
    Liu, Hongri
    Wang, Bailing
    ELECTRONICS, 2023, 12 (04)
  • [28] Anomaly Detection of the Brake Operating Unit on Metro Vehicles Using a One-Class LSTM Autoencoder
    Kang, Jaeyong
    Kim, Chul-Su
    Kang, Jeong Won
    Gwak, Jeonghwan
    APPLIED SCIENCES-BASEL, 2021, 11 (19):
  • [29] Optimization of Network Intrusion Detection System Using Genetic Algorithm with Improved Feature Selection Technique
    Matel, Elmer C.
    Sison, Arid M.
    Medina, Ruji P.
    2019 IEEE 11TH INTERNATIONAL CONFERENCE ON HUMANOID, NANOTECHNOLOGY, INFORMATION TECHNOLOGY, COMMUNICATION AND CONTROL, ENVIRONMENT, AND MANAGEMENT (HNICEM), 2019,
  • [30] CSE-IDS: Using cost-sensitive deep learning and ensemble algorithms to handle class imbalance in network-based intrusion detection systems
    Gupta, Neha
    Jindal, Vinita
    Bedi, Punam
    COMPUTERS & SECURITY, 2022, 112