Evolving cybersecurity frontiers: A comprehensive survey on concept drift and feature dynamics aware machine and deep learning in intrusion detection systems

被引:5
作者
Shyaa, Methaq A. [1 ]
Ibrahim, Noor Farizah [1 ]
Zainol, Zurinahni [1 ,2 ]
Abdullah, Rosni [1 ]
Anbar, Mohammed [3 ]
Alzubaidi, Laith [4 ,5 ]
机构
[1] Univ Sains Malaysia, Sch Comp Sci, Gelugor 11800, Pulau Penang, Malaysia
[2] Albukhary Int Univ, Sch Comp & Informat, Alor Setar 05200, Kedah, Malaysia
[3] Univ Sains Malaysia, Natl Adv Ctr IPv6 Nav6, Gelugor 11800, Penang, Malaysia
[4] Queensland Univ Technol, Sch Mech Med & Proc Engn, Brisbane, Qld 4000, Australia
[5] Queensland Univ Technol, Ctr Data Sci, Brisbane, Qld 4000, Australia
基金
澳大利亚研究理事会;
关键词
Concept drift; Feature Drift; Data stream; Cybersecurity; Intrusion detection; Online learning; PRINCIPAL COMPONENT ANALYSIS; DATA STREAMS; ENSEMBLE ALGORITHM; FEATURE-SELECTION; ONLINE; IOT; MODEL; REDUCTION; FRAMEWORK; CHARTS;
D O I
10.1016/j.engappai.2024.109143
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDS) have become pivotal in safeguarding information systems against evolving threats. Concurrently, Concept Drift presents a significant challenge in machine learning, affecting the adaptability and accuracy of predictive models in dynamic environments. Understanding the synergy between IDS and Concept Drift is crucial for developing robust security systems. The motivation behind this survey is driven by the emerging complexities in cyber threats and the dynamic nature of data streams, which necessitate advanced IDS capable of adapting to Concept and Feature Drift. Our analysis reveals a glaring omission in the existing literature-the integration of Concept Drift and Feature Drift within IDS. Most studies have focused on Concept Drift in a general context or on IDS but have yet to comprehensively consider the implications of data dynamics. This oversight has led to a fragmented understanding and suboptimal approaches to tackling modern cyber threats. To address this, we propose a comprehensive review that delves into the role of machine learning in IDS, explicitly focusing on Concept and Feature Drift. We have proposed a framework that includes all the necessary components for a drift-aware IDS. The framework incorporates dynamic feature selection, adaptive learning algorithms, and continuous monitoring techniques to handle Concept Drift and Feature Drift effectively. The survey highlights state-of-the-art methodologies and current challenges in integrating these concepts. The methodology involves an exhaustive analysis of published works from 2019 to 2024, comparing and contrasting various models and approaches. This includes a detailed examination of Concept Drift-aware IDS methods, dynamic feature selection techniques, and the impact of high dimensionality in IDS. These quantitative improvements underscore the necessity for developing adaptive and resilient IDS. The survey uncovers under-represented areas in current research, paving the way for future investigations. By highlighting these gaps and providing comparative data, the survey sets a clear direction for upcoming research efforts to foster the development of more dynamic and adaptable IDS solutions. The quantitative experimental evaluation of the proposed framework is planned to be conducted in a future article, where we will assess its effectiveness and performance in realworld scenarios.
引用
收藏
页数:34
相关论文
共 229 条
[11]   Network intrusion detection system: A systematic study of machine learning and deep learning approaches [J].
Ahmad, Zeeshan ;
Shahid Khan, Adnan ;
Wai Shiang, Cheah ;
Abdullah, Johari ;
Ahmad, Farhan .
TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (01)
[12]   Smart Traffic Shaping Based on Distributed Reinforcement Learning for Multimedia Streaming over 5G-VANET Communication Technology [J].
Ahmed, Adel A. ;
Malebary, Sharaf J. ;
Ali, Waleed ;
Barukab, Omar M. .
MATHEMATICS, 2023, 11 (03)
[13]   Cyber-Attack Prediction Based on Network Intrusion Detection Systems for Alert Correlation Techniques: A Survey [J].
Albasheer, Hashim ;
Siraj, Maheyzah Md ;
Mubarakali, Azath ;
Tayfour, Omer Elsier ;
Salih, Sayeed ;
Hamdan, Mosab ;
Khan, Suleman ;
Zainal, Anazida ;
Kamarudeen, Sameer .
SENSORS, 2022, 22 (04)
[14]   Toward Efficient Intrusion Detection System Using Hybrid Deep Learning Approach [J].
Aldallal, Ammar .
SYMMETRY-BASEL, 2022, 14 (09)
[15]   Intrusion Detection Systems: A State-of-the-Art Taxonomy and Survey [J].
Alkasassbeh, Mouhammd ;
Baddar, Sherenaz Al-Haj .
ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2023, 48 (08) :10021-10064
[16]  
Alqahtani AH, 2024, Arxiv, DOI arXiv:2404.01109
[17]   TON_IoT Telemetry Dataset: A New Generation Dataset of IoT and IIoT for Data-Driven Intrusion Detection Systems [J].
Alsaedi, Abdullah ;
Moustafa, Nour ;
Tari, Zahir ;
Mahmood, Abdun ;
Anwar, Adnan .
IEEE ACCESS, 2020, 8 :165130-165150
[18]   Concept Drift Analysis and Malware Attack Detection System Using Secure Adaptive Windowing [J].
Alsuwat, Emad ;
Solaiman, Suhare ;
Alsuwat, Hatim .
CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 75 (02) :3743-3759
[19]   Handling imbalanced data with concept drift by applying dynamic sampling and ensemble classification model [J].
Ancy, S. ;
Paulraj, D. .
COMPUTER COMMUNICATIONS, 2020, 153 :553-560
[20]   Recurring concept meta-learning for evolving data streams [J].
Anderson, Robert ;
Koh, Yun Sing ;
Dobbie, Gillian ;
Bifet, Albert .
EXPERT SYSTEMS WITH APPLICATIONS, 2019, 138