Affiliation:
1. School of Computer Science and Engineering, Anhui University of Science and Technology, Huainan 232001, China
Abstract
The increasing prevalence of unknown-type attacks on the Internet highlights the importance of developing efficient intrusion detection systems. While machine learning-based techniques can detect unknown types of attacks, the need for innovative approaches becomes evident, as traditional methods may not be sufficient. In this research, we propose a deep learning-based solution called the log-cosh variational autoencoder (LVAE) to address this challenge. The LVAE inherits the strong modeling abilities of the variational autoencoder (VAE), enabling it to understand complex data distributions and generate reconstructed data. To better simulate discrete features of real attacks and generate unknown types of attacks, we introduce an effective reconstruction loss term utilizing the logarithmic hyperbolic cosine (log-cosh) function in the LVAE. Compared to conventional VAEs, the LVAE shows promising potential in generating data that closely resemble unknown attacks, which is a critical capability for improving the detection rate of unknown attacks. In order to classify the generated unknown data, we employed eight feature extraction and classification techniques. Numerous experiments were conducted using the latest CICIDS2017 dataset, training with varying amounts of real and unknown-type attacks. Our optimal experimental results surpassed several state-of-the-art techniques, achieving accuracy and average F1 scores of 99.89% and 99.83%, respectively. The suggested LVAE strategy also demonstrated outstanding performance in generating unknown attack data. Overall, our work establishes a solid foundation for accurately and efficiently identifying unknown types of attacks, contributing to the advancement of intrusion detection techniques.
Funder
Project of Key Research and Development Program of Anhui Province
China National Natural Science Foundation
Subject
Fluid Flow and Transfer Processes,Computer Science Applications,Process Chemistry and Technology,General Engineering,Instrumentation,General Materials Science
Reference53 articles.
1. Network Abnormal Traffic Detection Model Based on Semi-Supervised Deep Reinforcement Learning;Dong;IEEE Trans. Netw. Serv. Manag.,2021
2. Alahmed, S., Alasad, Q., Hammood, M.M., Yuan, J.-S., and Alawad, M. (2022). Mitigation of Black-Box Attacks on Intrusion Detection Systems-Based ML. Computers, 11.
3. Ahmad, S., Arif, F., Zabeehullah, Z., and Iltaf, N. (2020, January 22–24). Novel Approach Using Deep Learning for Intrusion Detection and Classification of the Network Traffic. Proceedings of the 2020 IEEE International Conference on Computational Intelligence and Virtual Environments for Measurement Systems and Applications (CIVEMSA), Tunis, Tunisia.
4. Rigaki, M. (2017, January 18–20). Adversarial Deep Learning against Intrusion Detection Classifiers. Proceedings of the IST-152 Workshop on Intelligent Autonomous Agents for Cyber Defence and Resilience, Prague, Czech Republic.
5. Alasad, Q., Hammood, M.M., and Alahmed, S. (2022, January 2–3). Performance and Complexity Tradeoffs of Feature Selection on Intrusion Detection System-Based Neural Network Classification with High-Dimensional Dataset. Proceedings of the 2nd International Conference on Emerging Technologies and Intelligent Systems, Online.
Cited by
3 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献