On learning effective ensembles of deep neural networks for intrusion detection

被引:36
|
作者
Folino, F. [1 ]
Folino, G. [1 ]
Guarascio, M. [1 ]
Pisani, F. S. [1 ]
Pontieri, L. [1 ]
机构
[1] ICAR CNR, Inst High Performance Comp & Networking, Via P Bucci, I-87036 Arcavacata Di Rende, CS, Italy
基金
欧盟地平线“2020”;
关键词
Ensemble learning; Deep learning; Intrusion Detection Systems; SYSTEMS; MACHINE;
D O I
10.1016/j.inffus.2021.02.007
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Classification-oriented Machine Learning methods are a precious tool, in modern Intrusion Detection Systems (IDSs), for discriminating between suspected intrusion attacks and normal behaviors. Many recent proposals in this field leveraged Deep Neural Network (DNN) methods, capable of learning effective hierarchical data representations automatically. However, many of these solutions were validated on data featuring stationary distributions and/or large amounts of training examples. By contrast, in real IDS applications different kinds of attack tend to occur over time, and only a small fraction of the data instances is labeled (usually with far fewer examples of attacks than of normal behavior). A novel ensemble-based Deep Learning framework is proposed here that tries to face the challenging issues above. Basically, the non-stationary nature of IDS log data is faced by maintaining an ensemble consisting of a number of specialized base DNN classifiers, trained on disjoint chunks of the data instances? stream, plus a combiner model (reasoning on both the base classifiers predictions and original instance features). In order to learn deep base classifiers effectively from small training samples, an ad-hoc shared DNN architecture is adopted, featuring a combination of dropout capabilities, skip connections, along with a cost-sensitive loss (for dealing with unbalanced data). Tests results, conducted on two benchmark IDS datasets and involving several competitors, confirmed the effectiveness of our proposal (in terms of both classification accuracy and robustness to data scarcity), and allowed us to evaluate different ensemble combination schemes.
引用
收藏
页码:48 / 69
页数:22
相关论文
共 50 条
  • [31] An Effective Intrusion Detection Model Based on Random Forest and Neural Networks
    Zhong, Shaohong
    Huang, Huajun
    Chen, Aibin
    [J]. MANUFACTURING SYSTEMS AND INDUSTRY APPLICATIONS, 2011, 267 : 308 - 313
  • [32] Active Learning for Deep Detection Neural Networks
    Aghdam, Hamed H.
    Gonzalez-Garcia, Abel
    van de Weijer, Joost
    Lopez, Antonio M.
    [J]. 2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 3671 - 3679
  • [33] Intrusion Detection System Based on Deep Neural Network and Incremental Learning for In-Vehicle CAN Networks
    Lin, Jiaying
    Wei, Yehua
    Li, Wenjia
    Long, Jing
    [J]. UBIQUITOUS SECURITY, 2022, 1557 : 255 - 267
  • [34] Enhanced Network Intrusion Detection using Deep Convolutional Neural Networks
    Naseer, Sheraz
    Saleem, Yasir
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (10): : 5159 - 5178
  • [35] DeepShield: A Hybrid Deep Learning Approach for Effective Network Intrusion Detection
    Lin, Hongjie
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (07) : 1094 - 1104
  • [36] Intrusion Detection Framework for CAN Networks Based on Evidence Deep Learning
    Shi, Qin
    Li, Zhiwei
    Cheng, Teng
    Zhang, Qiang
    Wang, Wenchong
    [J]. Qiche Gongcheng/Automotive Engineering, 2024, 46 (11): : 2039 - 2045
  • [37] Intrusion Detection System Through Deep Learning in Routing MANET Networks
    Abbood, Zainab Ali
    Atilla, Dogu Cagdas
    Aydin, Cagatay
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2023, 37 (01): : 268 - 281
  • [38] Improved competitive learning neural networks for network intrusion and fraud detection
    Lei, John Zhong
    Ghorbani, Ali A.
    [J]. NEUROCOMPUTING, 2012, 75 (01) : 135 - 145
  • [39] Intrusion detection models for IOT networks via deep learning approaches
    Madhu, Bhukya
    Venu Gopala Chari, M.
    Vankdothu, Ramdas
    Silivery, Arun Kumar
    Aerranagula, Veerender
    [J]. Measurement: Sensors, 2023, 25
  • [40] A novel method for effective intrusion detection based on convolutional speaking neural networks
    Xie, Ying
    Chen, Hong
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2024, 36 (02)