ESVI-GaMM: A fast network intrusion detection approach based on the Bayesian gamma mixture model

被引:0
作者
He, Wenda [1 ]
Cai, Xiangrui [1 ]
Lai, Yuping [2 ]
Yuan, Xiaojie [1 ]
机构
[1] Nankai Univ, Coll Comp Sci, TKLNDST, Tianjin, Peoples R China
[2] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Bayesian inference; Gamma mixture model; Extended stochastic variational inference; Network intrusion detection; ANOMALY DETECTION; DETECTION SYSTEM; CLASSIFIER; MACHINE;
D O I
10.1016/j.ins.2024.121001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the application of networks permeates various aspects of daily life, maintaining network security has become a crucial challenge. A network intrusion detection system (NIDS) functions as a critical technique for securing cyberspace and has gained considerable attention. Although researchers have made significant progress in developing NIDSs, challenges still exist in high -speed networks with overwhelming network traffic. Existing methods largely focus on improving model detection accuracy and often overlook speed and computational efficiency. This oversight renders most current methods impractical for real -world high -speed network scenarios. To address this issue, we propose an innovative and efficient network intrusion detection algorithm, namely, the Bayesian gamma mixture model (GaMM) classifier. With the recently proposed extended stochastic variational inference (ESVI) framework, we introduce lower-bound approximations to the evidence lower bound (ELBO), namely, the original variational object function. An analytically tractable Bayesian estimation algorithm for a GaMM is derived through stochastic optimization of the obtained lower bound and we validate its performance and computational efficiency on three publicly available datasets (CICMalmem2022, OPCUA, and CICIDS2018). The experimental results indicate that the proposed classifier not only achieves a detection performance comparable to that of other benchmark models but also significantly reduces both the training and detection times.
引用
收藏
页数:13
相关论文
共 49 条
[1]   A novel weighted support vector machines multiclass classifier based on differential evolution for intrusion detection systems [J].
Aburomman, Abdulla Amin ;
Reaz, Mamun Bin Ibne .
INFORMATION SCIENCES, 2017, 414 :225-246
[2]   Performance Comparison of Support Vector Machine, Random Forest, and Extreme Learning Machine for Intrusion Detection [J].
Ahmad, Iftikhar ;
Basheri, Mohammad ;
Iqbal, Muhammad Javed ;
Rahim, Aneel .
IEEE ACCESS, 2018, 6 :33789-33795
[3]   A new DDoS attacks intrusion detection model based on deep learning for cybersecurity [J].
Akgun, Devrim ;
Hizal, Selman ;
Cavusoglu, Unal .
COMPUTERS & SECURITY, 2022, 118
[4]  
Alahmadi BA, 2022, PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, P2783
[5]   Network Anomaly Intrusion Detection Using a Nonparametric Bayesian Approach and Feature Selection [J].
Alhakami, Wajdi ;
Alharbi, Abdullah ;
Bourouis, Sami ;
Alroobaea, Roobaea ;
Bouguila, Nizar .
IEEE ACCESS, 2019, 7 :52181-52190
[6]   Security attacks in Opportunistic Mobile Networks: A systematic literature review [J].
Altaweel, Ala ;
Aslam, Sidra ;
Kamel, Ibrahim .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 221
[7]   Autoencoder-based deep metric learning for network intrusion detection [J].
Andresini, Giuseppina ;
Appice, Annalisa ;
Malerba, Donato .
INFORMATION SCIENCES, 2021, 569 (569) :706-727
[8]  
Bartos K, 2016, PROCEEDINGS OF THE 25TH USENIX SECURITY SYMPOSIUM, P807
[9]   Detecting Regions of Maximal Divergence for Spatio-Temporal Anomaly Detection [J].
Barz, Bjorn ;
Rodner, Erik ;
Garcia, Yanira Guanche ;
Denzler, Joachim .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2019, 41 (05) :1088-1101
[10]   Positive vectors clustering using inverted Dirichlet finite mixture models [J].
Bdiri, Taoufik ;
Bouguila, Nizar .
EXPERT SYSTEMS WITH APPLICATIONS, 2012, 39 (02) :1869-1882