Evolving cybersecurity frontiers: A comprehensive survey on concept drift and feature dynamics aware machine and deep learning in intrusion detection systems

被引:5
作者
Shyaa, Methaq A. [1 ]
Ibrahim, Noor Farizah [1 ]
Zainol, Zurinahni [1 ,2 ]
Abdullah, Rosni [1 ]
Anbar, Mohammed [3 ]
Alzubaidi, Laith [4 ,5 ]
机构
[1] Univ Sains Malaysia, Sch Comp Sci, Gelugor 11800, Pulau Penang, Malaysia
[2] Albukhary Int Univ, Sch Comp & Informat, Alor Setar 05200, Kedah, Malaysia
[3] Univ Sains Malaysia, Natl Adv Ctr IPv6 Nav6, Gelugor 11800, Penang, Malaysia
[4] Queensland Univ Technol, Sch Mech Med & Proc Engn, Brisbane, Qld 4000, Australia
[5] Queensland Univ Technol, Ctr Data Sci, Brisbane, Qld 4000, Australia
基金
澳大利亚研究理事会;
关键词
Concept drift; Feature Drift; Data stream; Cybersecurity; Intrusion detection; Online learning; PRINCIPAL COMPONENT ANALYSIS; DATA STREAMS; ENSEMBLE ALGORITHM; FEATURE-SELECTION; ONLINE; IOT; MODEL; REDUCTION; FRAMEWORK; CHARTS;
D O I
10.1016/j.engappai.2024.109143
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDS) have become pivotal in safeguarding information systems against evolving threats. Concurrently, Concept Drift presents a significant challenge in machine learning, affecting the adaptability and accuracy of predictive models in dynamic environments. Understanding the synergy between IDS and Concept Drift is crucial for developing robust security systems. The motivation behind this survey is driven by the emerging complexities in cyber threats and the dynamic nature of data streams, which necessitate advanced IDS capable of adapting to Concept and Feature Drift. Our analysis reveals a glaring omission in the existing literature-the integration of Concept Drift and Feature Drift within IDS. Most studies have focused on Concept Drift in a general context or on IDS but have yet to comprehensively consider the implications of data dynamics. This oversight has led to a fragmented understanding and suboptimal approaches to tackling modern cyber threats. To address this, we propose a comprehensive review that delves into the role of machine learning in IDS, explicitly focusing on Concept and Feature Drift. We have proposed a framework that includes all the necessary components for a drift-aware IDS. The framework incorporates dynamic feature selection, adaptive learning algorithms, and continuous monitoring techniques to handle Concept Drift and Feature Drift effectively. The survey highlights state-of-the-art methodologies and current challenges in integrating these concepts. The methodology involves an exhaustive analysis of published works from 2019 to 2024, comparing and contrasting various models and approaches. This includes a detailed examination of Concept Drift-aware IDS methods, dynamic feature selection techniques, and the impact of high dimensionality in IDS. These quantitative improvements underscore the necessity for developing adaptive and resilient IDS. The survey uncovers under-represented areas in current research, paving the way for future investigations. By highlighting these gaps and providing comparative data, the survey sets a clear direction for upcoming research efforts to foster the development of more dynamic and adaptable IDS solutions. The quantitative experimental evaluation of the proposed framework is planned to be conducted in a future article, where we will assess its effectiveness and performance in realworld scenarios.
引用
收藏
页数:34
相关论文
共 229 条
  • [1] ElStream: An Ensemble Learning Approach for Concept Drift Detection in Dynamic Social Big Data Stream Learning
    Abbasi, Ahmad
    Javed, Abdul Rehman
    Chakraborty, Chinmay
    Nebhen, Jamel
    Zehra, Wisha
    Jalil, Zunera
    [J]. IEEE ACCESS, 2021, 9 : 66408 - 66419
  • [2] Principal component analysis
    Abdi, Herve
    Williams, Lynne J.
    [J]. WILEY INTERDISCIPLINARY REVIEWS-COMPUTATIONAL STATISTICS, 2010, 2 (04): : 433 - 459
  • [3] Abdulganiyu O.H., 2023, PREPRINT, DOI [10.1007/s11276-023-03495-2Preprint, DOI 10.1007/S11276-023-03495-2PREPRINT]
  • [4] A systematic literature review for network intrusion detection system (IDS)
    Abdulganiyu, Oluwadamilare Harazeem
    Tchakoucht, Taha Ait
    Saheed, Yakub Kayode
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (05) : 1125 - 1162
  • [5] An Intrusion Detection System for the Internet of Things Based on Machine Learning: Review and Challenges
    Adnan, Ahmed
    Muhammed, Abdullah
    Abd Ghani, Abdul Azim
    Abdullah, Azizol
    Hakim, Fahrul
    [J]. SYMMETRY-BASEL, 2021, 13 (06):
  • [6] Hyper-Heuristic Framework for Sequential Semi-Supervised Classification Based on Core Clustering
    Adnan, Ahmed
    Muhammed, Abdullah
    Abd Ghani, Abdul Azim
    Abdullah, Azizol
    Hakim, Fahrul
    [J]. SYMMETRY-BASEL, 2020, 12 (08):
  • [7] Adaptive PCA-based feature drift detection using statistical measure
    Agrahari, Supriya
    Singh, Anil Kumar
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2022, 25 (06): : 4481 - 4494
  • [8] Concept Drift Detection in Data Stream Mining : A literature review
    Agrahari, Supriya
    Singh, Anil Kumar
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 9523 - 9540
  • [9] Aguiar G., 2023, PREPRINT, DOI [10.1007/s10994-023-06353-6Preprint, DOI 10.1007/S10994-023-06353-6PREPRINT]
  • [10] An Efficient Network Intrusion Detection and Classification System
    Ahmad, Iftikhar
    Ul Haq, Qazi Emad
    Imran, Muhammad
    Alassafi, Madini O.
    AlGhamdi, Rayed A.
    [J]. MATHEMATICS, 2022, 10 (03)