APELID: Enhancing real-time intrusion detection with augmented WGAN and parallel ensemble learning

被引:20
作者
Vo, Hoang V. [1 ]
Du, Hanh P. [1 ]
Nguyen, Hoa N. [1 ]
机构
[1] Vietnam Natl Univ Hanoi, VNU Univ Engn & Technol, Dept Informat Syst, Hanoi 100000, Vietnam
关键词
AI-powered intrusion detection; Traffic deep analysis; Data augmentation; Wasserstein generative adversarial networks; Deep neural network; EXtreme gradient boosting; Gradient boosting on decision trees; Bagging meta-estimator; Parallel ensemble learning; NEURAL-NETWORK; CLASSIFICATION; MODEL;
D O I
10.1016/j.cose.2023.103567
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper proposes an AI-powered intrusion detection method that improves intrusion detection performance by increasing the quality of the training set and employing numerous potent AI models. Composed of the Augmented Wasserstein Generative Adversarial Networks (AWGAN) and Parallel Ensemble Learning-based Intrusion Detection (PELID) algorithms, it is referred to as APELID. First, to augment the training set quality, AWGAN combines a clustering algorithm to select representative samples from the majority classes and WGAN to generate more realistic samples from the minority classes. Second, PELID employs a weighted ensemble of multiple efficient AI models in parallel to improve the efficacy of AI-powered intrusion detection. In addition, APELID also incorporates a sandbox-based malware analyzer. It aims to enrich the indicators of compromise for preventing malicious files that have been transferred over the network. Rigorous experiments utilizing well-known datasets, such as CSE-CIC-IDS2018 and NSL-KDD, are conducted in order to evaluate APELID. Hence, it achieves an outstanding F1-score of 99.99% and 99.65% and a remarkably low false negative rate of 0.00% and 0.34%, respectively, which is superior to state-of-the-art methods. In addition, the average PELID-based detection time (i.e., 22.29 mu s/flow) for a single network traffic flow is fast enough to detect intrusions in real-time.
引用
收藏
页数:14
相关论文
共 58 条
[21]  
Gouveia A., 2020, Recent Advances in Security, Privacy, and Trust for Internet of Things (IoT) and Cyber-Physical Systems (CPS), V1, P150
[22]   CSE-IDS: Using cost-sensitive deep learning and ensemble algorithms to handle class imbalance in network-based intrusion detection systems [J].
Gupta, Neha ;
Jindal, Vinita ;
Bedi, Punam .
COMPUTERS & SECURITY, 2022, 112
[23]   MMM-RF: A novel high accuracy multinomial mixture model for network intrusion detection systems [J].
Hammad, Mohamed ;
Hewahi, Nabil ;
Elmedany, Wael .
COMPUTERS & SECURITY, 2022, 120
[24]   Anomaly Detection Using XGBoost Ensemble of Deep Neural Network Models [J].
Ikram, Sumaiya Thaseen ;
Cherukuri, Aswani Kumar ;
Poorva, Babu ;
Ushasree, Pamidi Sai ;
Zhang, Yishuo ;
Liu, Xiao ;
Li, Gang .
CYBERNETICS AND INFORMATION TECHNOLOGIES, 2021, 21 (03) :175-188
[25]  
Jamalpur S, 2018, PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), P1056, DOI 10.1109/ICICCT.2018.8473346
[26]   PIGNUS: A Deep Learning model for IDS in industrial internet-of-things [J].
Jayalaxmi, P. L. S. ;
Saha, Rahul ;
Kumar, Gulshan ;
Alazab, Mamoun ;
Conti, Mauro ;
Cheng, Xiaochun .
COMPUTERS & SECURITY, 2023, 132
[27]   Classification of Imbalanced Data by Combining the Complementary Neural Network and SMOTE Algorithm [J].
Jeatrakul, Piyasak ;
Wong, Kok Wai ;
Fung, Chun Che .
NEURAL INFORMATION PROCESSING: MODELS AND APPLICATIONS, PT II, 2010, 6444 :152-159
[28]  
Ke GL, 2017, ADV NEUR IN, V30
[29]   An Efficient Hybrid Webshell Detection Method for Webserver of Marine Transportation Systems [J].
Le, Ha, V ;
Nguyen, Tu N. ;
Nguyen, Hoa N. ;
Le, Linh .
IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (02) :2630-2642
[30]   GAN-based imbalanced data intrusion detection system [J].
Lee, JooHwa ;
Park, KeeHyun .
PERSONAL AND UBIQUITOUS COMPUTING, 2021, 25 (01) :121-128