On learning effective ensembles of deep neural networks for intrusion detection

被引:36
|
作者
Folino, F. [1 ]
Folino, G. [1 ]
Guarascio, M. [1 ]
Pisani, F. S. [1 ]
Pontieri, L. [1 ]
机构
[1] ICAR CNR, Inst High Performance Comp & Networking, Via P Bucci, I-87036 Arcavacata Di Rende, CS, Italy
基金
欧盟地平线“2020”;
关键词
Ensemble learning; Deep learning; Intrusion Detection Systems; SYSTEMS; MACHINE;
D O I
10.1016/j.inffus.2021.02.007
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Classification-oriented Machine Learning methods are a precious tool, in modern Intrusion Detection Systems (IDSs), for discriminating between suspected intrusion attacks and normal behaviors. Many recent proposals in this field leveraged Deep Neural Network (DNN) methods, capable of learning effective hierarchical data representations automatically. However, many of these solutions were validated on data featuring stationary distributions and/or large amounts of training examples. By contrast, in real IDS applications different kinds of attack tend to occur over time, and only a small fraction of the data instances is labeled (usually with far fewer examples of attacks than of normal behavior). A novel ensemble-based Deep Learning framework is proposed here that tries to face the challenging issues above. Basically, the non-stationary nature of IDS log data is faced by maintaining an ensemble consisting of a number of specialized base DNN classifiers, trained on disjoint chunks of the data instances? stream, plus a combiner model (reasoning on both the base classifiers predictions and original instance features). In order to learn deep base classifiers effectively from small training samples, an ad-hoc shared DNN architecture is adopted, featuring a combination of dropout capabilities, skip connections, along with a cost-sensitive loss (for dealing with unbalanced data). Tests results, conducted on two benchmark IDS datasets and involving several competitors, confirmed the effectiveness of our proposal (in terms of both classification accuracy and robustness to data scarcity), and allowed us to evaluate different ensemble combination schemes.
引用
收藏
页码:48 / 69
页数:22
相关论文
共 50 条
  • [21] A deep learning technique for intrusion detection system using a Recurrent Neural Networks based framework
    Kasongo, Sydney Mambwe
    [J]. COMPUTER COMMUNICATIONS, 2023, 199 : 113 - 125
  • [22] Effective network intrusion detection by addressing class imbalance with deep neural networks multimedia tools and applications
    Manisha Rani
    [J]. Multimedia Tools and Applications, 2022, 81 : 8499 - 8518
  • [23] Effective network intrusion detection by addressing class imbalance with deep neural networks multimedia tools and applications
    Rani, Manisha
    Gagandeep
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (06) : 8499 - 8518
  • [24] Activation Ensembles for Deep Neural Networks
    Klabjan, Diego
    Harmon, Mark
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 206 - 214
  • [25] A Hybrid Deep Learning Approach for Intrusion Detection in IoT Networks
    Emec, Murat
    Ozcanhan, Mehmet Hilal
    [J]. ADVANCES IN ELECTRICAL AND COMPUTER ENGINEERING, 2022, 22 (01) : 3 - 12
  • [26] Intrusion Detection in IoT Networks Using Deep Learning Algorithm
    Susilo, Bambang
    Sari, Riri Fitri
    [J]. INFORMATION, 2020, 11 (05)
  • [27] Deep Learning-based Intrusion Detection for IoT Networks
    Ge, Mengmeng
    Fu, Xiping
    Syed, Naeem
    Baig, Zubair
    Teo, Gideon
    Robles-Kelly, Antonio
    [J]. 2019 IEEE 24TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC 2019), 2019, : 256 - 265
  • [28] Federated Deep Learning for Collaborative Intrusion Detection in Heterogeneous Networks
    Popoola, Segun, I
    Qui, Guan
    Adebisi, Bamidele
    Hammoudeh, Mohammad
    Gacanin, Haris
    [J]. 2021 IEEE 94TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2021-FALL), 2021,
  • [29] Intrusion Detection Using Convolutional Neural Networks for Representation Learning
    Li, Zhipeng
    Qin, Zheng
    Huang, Kai
    Yang, Xiao
    Ye, Shuxiong
    [J]. NEURAL INFORMATION PROCESSING, ICONIP 2017, PT V, 2017, 10638 : 858 - 866
  • [30] Intrusion detection with neural networks
    Ryan, J
    Lin, MJ
    Miikkulainen, R
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 10, 1998, 10 : 943 - 949