On learning effective ensembles of deep neural networks for intrusion detection

被引:36
|
作者
Folino, F. [1 ]
Folino, G. [1 ]
Guarascio, M. [1 ]
Pisani, F. S. [1 ]
Pontieri, L. [1 ]
机构
[1] ICAR CNR, Inst High Performance Comp & Networking, Via P Bucci, I-87036 Arcavacata Di Rende, CS, Italy
基金
欧盟地平线“2020”;
关键词
Ensemble learning; Deep learning; Intrusion Detection Systems; SYSTEMS; MACHINE;
D O I
10.1016/j.inffus.2021.02.007
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Classification-oriented Machine Learning methods are a precious tool, in modern Intrusion Detection Systems (IDSs), for discriminating between suspected intrusion attacks and normal behaviors. Many recent proposals in this field leveraged Deep Neural Network (DNN) methods, capable of learning effective hierarchical data representations automatically. However, many of these solutions were validated on data featuring stationary distributions and/or large amounts of training examples. By contrast, in real IDS applications different kinds of attack tend to occur over time, and only a small fraction of the data instances is labeled (usually with far fewer examples of attacks than of normal behavior). A novel ensemble-based Deep Learning framework is proposed here that tries to face the challenging issues above. Basically, the non-stationary nature of IDS log data is faced by maintaining an ensemble consisting of a number of specialized base DNN classifiers, trained on disjoint chunks of the data instances? stream, plus a combiner model (reasoning on both the base classifiers predictions and original instance features). In order to learn deep base classifiers effectively from small training samples, an ad-hoc shared DNN architecture is adopted, featuring a combination of dropout capabilities, skip connections, along with a cost-sensitive loss (for dealing with unbalanced data). Tests results, conducted on two benchmark IDS datasets and involving several competitors, confirmed the effectiveness of our proposal (in terms of both classification accuracy and robustness to data scarcity), and allowed us to evaluate different ensemble combination schemes.
引用
收藏
页码:48 / 69
页数:22
相关论文
共 50 条
  • [41] Neural Networks for Intrusion Detection Systems
    Beqiri, Elidon
    [J]. GLOBAL SECURITY, SAFETY, AND SUSTAINABILITY, PROCEEDINGS, 2009, 45 : 156 - 165
  • [42] Agents and Neural Networks for Intrusion Detection
    Herrero, Alvaro
    Corchado, Emilio
    [J]. PROCEEDINGS OF THE INTERNATIONAL WORKSHOP ON COMPUTATIONAL INTELLIGENCE IN SECURITY FOR INFORMATION SYSTEMS CISIS 2008, 2009, 53 : 155 - 162
  • [43] Relay Backpropagation for Effective Learning of Deep Convolutional Neural Networks
    Shen, Li
    Lin, Zhouchen
    Huang, Qingming
    [J]. COMPUTER VISION - ECCV 2016, PT VII, 2016, 9911 : 467 - 482
  • [44] Intrusion Detection System based on Network Traffic using Deep Neural Networks
    Chamou, Dimitra
    Toupas, Petros
    Ketzaki, Eleni
    Papadopoulos, Stavros
    Giannoutakis, Konstantinos M.
    Drosou, Anastasios
    Tzovaras, Dimitrios
    [J]. 2019 IEEE 24TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (IEEE CAMAD), 2019,
  • [45] Effective deep neural networks for license plate detection and recognition
    The-Anh Pham
    [J]. The Visual Computer, 2023, 39 : 927 - 941
  • [46] Deep Recurrent Neural Network for Intrusion Detection in SDN-based Networks
    Tang, Tuan A.
    Mhamdi, Lotfi
    McLernon, Des
    Zaidi, Syed Ali Raza
    Ghogho, Mounir
    [J]. 2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 202 - 206
  • [47] Effective deep neural networks for license plate detection and recognition
    The-Anh Pham
    [J]. VISUAL COMPUTER, 2023, 39 (03): : 927 - 941
  • [48] An intrusion detection system for wireless sensor networks using deep neural network
    Gowdhaman, V
    Dhanapal, R.
    [J]. SOFT COMPUTING, 2022, 26 (23) : 13059 - 13067
  • [49] New Improved Training for Deep Neural Networks Based on Intrusion Detection System
    Benmessahel, Ilyas
    Xie, Kun
    Chellal, Mouna
    [J]. 2018 2ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE APPLICATIONS AND TECHNOLOGIES (AIAAT 2018), 2018, 435
  • [50] Hybrid intrusion detection and signature generation using Deep Recurrent Neural Networks
    Kaur, Sanmeet
    Singh, Maninder
    [J]. NEURAL COMPUTING & APPLICATIONS, 2020, 32 (12): : 7859 - 7877