Network-based Intrusion Detection: A One-class Classification Approach

PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022(2022)

Cited 3|Views3
No score
Abstract
The adoption of new technologies and the increasing amount of connected devices have drawn the attention of cyberattackers, whose intentions are oriented to disturb computational services or even steal critical information. This poses new challenges in the design of Intrusion Detection Systems (IDS), which are in charge of detecting threats. When dealing with unknown cyber-attacks, anomaly-based IDS (AIDS) have drawn the attention of the research community, since they could detect, for instance, zero-day attacks. A recurrent critical aspect in the design of these systems is the training procedures. In the context of attack detection, training involves difficulties due to the imbalanced nature (one class much more represented than the other) of the associated data sets. Hence, approaches to address the class imbalance are always relevant. In this work, we present the evaluation of different machine learning (ML) algorithms, known as one-class classifiers, that hold the potential to be implemented over an AIDS. For this task, we used the UNSWNB15, comparing their performance using pertinent metrics that are normally used to assess an attack detection algorithm.
More
Translated text
Key words
Intrusion detection, Anomaly, security, NIDS
AI Read Science
Must-Reading Tree
Example
Generate MRT to find the research sequence of this paper
Chat Paper
Summary is being generated by the instructions you defined