Expanding analytical capabilities in intrusion detection through ensemble-based multi-label classification

被引:7
作者
Hallaji, Ehsan [1 ]
Razavi-Far, Roozbeh [1 ,2 ]
Saif, Mehrdad [1 ]
机构
[1] Univ Windsor, Dept Elect & Comp Engn, 401 Sunset Ave, Windsor, ON N9B 3P4, Canada
[2] Univ New Brunswick, Fac Comp Sci, 550 Windsor St, Fredericton, NB E3B 5A3, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Multi-label learning; Deep learning; Ensemble learning; Intrusion detection; INTERNET; THINGS;
D O I
10.1016/j.cose.2024.103730
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection systems are primarily designed to flag security breaches upon their occurrence. These systems operate under the assumption of single -label data, where each instance is assigned to a single category. However, when dealing with complex data, such as malware triage, the information provided by the IDS is limited. Consequently, additional analysis becomes necessary, leading to delays and incurring additional computational costs. Existing solutions to this problem typically merge these steps by considering a unified, but large, label set encompassing both intrusion and analytical labels, which adversely affects efficiency and performance. To address these challenges, this paper presents a novel framework for multi -label classification by employing an ensemble of sequential models that preserve the original label sets during training. Each model focuses on learning the distribution specifically related to its assigned set of labels, independent of the other label sets. To capture the relationship between different sets of labels, the parameters of each trained model initialize the subsequent model, ensuring that information from unrelated label sets does not interfere with the learning objective. Consequently, the proposed method enhances prediction performance without increasing computational complexity. To evaluate the effectiveness of our approach, we conduct experiments on a realworld dataset related to intrusion detection. The results clearly demonstrate the effectiveness of our proposed method in handling multi -label classification tasks.
引用
收藏
页数:9
相关论文
共 31 条
[1]   SoK: Pragmatic Assessment of Machine Learning for Network Intrusion Detection [J].
Apruzzese, Giovanni ;
Laskov, Pavel ;
Schneider, Johannes .
2023 IEEE 8TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, EUROS&P, 2023, :592-614
[2]  
Arik SO, 2021, AAAI CONF ARTIF INTE, V35, P6679
[3]  
Arp D, 2022, PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, P3971
[4]   Learning multi-label scene classification [J].
Boutell, MR ;
Luo, JB ;
Shen, XP ;
Brown, CM .
PATTERN RECOGNITION, 2004, 37 (09) :1757-1771
[5]   CPS-GUARD: Intrusion detection for cyber-physical systems and IoT devices using outlier-aware deep autoencoders [J].
Catillo, Marta ;
Pecchia, Antonio ;
Villano, Umberto .
COMPUTERS & SECURITY, 2023, 129
[6]   XGBoost: A Scalable Tree Boosting System [J].
Chen, Tianqi ;
Guestrin, Carlos .
KDD'16: PROCEEDINGS OF THE 22ND ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2016, :785-794
[7]   Internet of Things: A survey on machine learning-based intrusion detection approaches [J].
da Costa, Kelton A. P. ;
Papa, Joao P. ;
Lisboa, Celso O. ;
Munoz, Roberto ;
de Albuquerque, Victor Hugo C. .
COMPUTER NETWORKS, 2019, 151 :147-157
[8]  
Devlin J, 2019, Arxiv, DOI arXiv:1810.04805
[9]   A comprehensive survey on network anomaly detection [J].
Fernandes, Gilberto ;
Rodrigues, Joel J. P. C. ;
Carvalho, Luiz Fernando ;
Al-Muhtadi, Jalal F. ;
Proenca, Mario Lemes, Jr. .
TELECOMMUNICATION SYSTEMS, 2019, 70 (03) :447-489
[10]   Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study [J].
Ferrag, Mohamed Amine ;
Maglaras, Leandros ;
Moschoyiannis, Sotiris ;
Janicke, Helge .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 50