Loading...
| Friend's email | |
| Your name | |
| Your email | |
| enter code | |
This page was sent successfuly
An adaptable deep learning-based intrusion detection system to zero-day attacks
Soltani, M ; Sharif University of Technology | 2023
111
Viewed
- Type of Document: Article
- DOI: 10.1016/j.jisa.2023.103516
- Publisher: Elsevier Ltd , 2023
- Abstract:
- The main challenge of an intrusion detection system (IDS) is detecting novelties (i.e., zero-day attacks) in addition to generating a report about the known attacks (i.e., classifying known attacks). Another challenge of an IDS is the adaptation to the detected novelties. For this purpose, it needs sufficient labeled samples of the new attacks. On the other hand, the labeling procedure is a time-consuming task for the security expert teams. This paper proposes a DL-based IDS framework adaptable to new attacks, consisting of different phases. The first phase uses deep learning-based open set recognition methods to identify unknown samples (i.e., new attacks), and make a report from different known attacks simultaneously. Then, the novel samples are clustered by combining the deep model and clustering algorithms. These clusters are the main key to making the labeling procedure more practical and reducing the time and effort of the expert knowledge team. Finally, we use the labeled groups to update the model and make it adaptable to new traffic behaviors. To evaluate the proposed framework, we compare our proposed DOC++ alongside different algorithms (including DOC, OpenMax, AutoSVM, and CROSR) in the open set recognition phase of the framework and use both the CIC-IDS2017 and CSE-CIC-IDS2018 data sets for the evaluation. Our results show that DOC++ achieves the best performance among the other open set recognition approaches. Besides, the completeness and homogeneity of the clustering phase prove that the generated labeled groups are good enough for the supervised labeling and updating phases. © 2023 Elsevier Ltd
- Keywords:
- Adaptable IDS ; Deep clustering ; Deep learning ; Novelty-based detectors ; Open set recognition ; Zero-day attacks
- Source: Journal of Information Security and Applications ; Volume 76 , 2023 ; 22142134 (ISSN)
- URL: https://www.sciencedirect.com/science/article/abs/pii/S221421262300100X
