Affiliation:
1. School of Communications, Nanjing Vocational College of Information Technology, Nanjing 210023, China
2. School of Modern Posts, Nanjing University of Posts & Telecommunications, Nanjing 210003, China
Abstract
With the rapid advancement of the Internet of Things, network security has garnered increasing attention from researchers. Applying deep learning (DL) has significantly enhanced the performance of Network Intrusion Detection Systems (NIDSs). However, due to its complexity and “black box” problem, deploying DL-based NIDS models in practical scenarios poses several challenges, including model interpretability and being lightweight. Feature selection (FS) in DL models plays a crucial role in minimizing model parameters and decreasing computational overheads while enhancing NIDS performance. Hence, selecting effective features remains a pivotal concern for NIDSs. In light of this, this paper proposes an interpretable feature selection method for encrypted traffic intrusion detection based on SHAP and causality principles. This approach utilizes the results of model interpretation for feature selection to reduce feature count while ensuring model reliability. We evaluate and validate our proposed method on two public network traffic datasets, CICIDS2017 and NSL-KDD, employing both a CNN and a random forest (RF). Experimental results demonstrate superior performance achieved by our proposed method.
Funder
Suzhou Fundamental Research Project
Suzhou Innovative Association Project
Reference37 articles.
1. IoT Equipment Monitoring System Based on C5. 0 Decision Tree and Time-series Analysis;Zhu;IEEE Access,2021
2. Rahul, A., Gupta, A., Raj, A., and Arora, M. (2021, January 8–10). IP Traffic Classification of 4G Network using Machine Learning Techniques. Proceedings of the 2021 5th International Conference on Computing Methodologies and Communication (ICCMC), Erode, India.
3. Performance analysis of machine learning models for intrusion detection system using Gini Impurity-based Weighted Random Forest (GIWRF) feature selection technique;Disha;Cybersecurity,2022
4. Deep learning-based intrusion detection systems: A systematic review;Lansky;IEEE Access,2021
5. Krizhevsky, A., Sutskever, I., and Hinton, G.E. (2012). Imagenet classification with deep convolutional neural networks. Adv. Neural Inf. Process. Syst., 25.