Hybrid Explainable Intrusion Detection System: Global vs. Local Approach

被引:0
|
作者
Tanuwidjaja, Harry Chandra [1 ]
Takahashi, Takeshi [1 ]
Lin, Tsung-Nan [2 ]
Lee, Boyi [3 ]
Ban, Tao [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Tokyo, Japan
[2] Natl Taiwan Univ, Taipei, Taiwan
[3] Natl Appl Res Labs, Taipei, Taiwan
来源
PROCEEDINGS OF THE 2023 WORKSHOP ON RECENT ADVANCES IN RESILIENT AND TRUSTWORTHY ML SYSTEMS IN AUTONOMOUS NETWORKS, ARTMAN 2023 | 2023年
关键词
IDS; explanation; XAI; X-IDS; local interpretable model-agnostic explanations; Shapley additive explanation;
D O I
10.1145/3605772.3624004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDSs) play a major role in detecting suspicious activities and alerting users of potential malicious adversaries. Security operators investigate these alerts and attempt to mitigate the risks and damage. Many IDS-related studies have focused on improving detection accuracy and reducing false positives; however, the operators need to understand the rationale behind IDS engines issuing an alert. In contrast to conventional rule-based engines, machine-learning-based engines use a detection mechanism that is like a black box, i.e., it is not designed to indicate a rationale. In this paper, we introduce an explainable IDS (X-IDS) that copes with the well-used XAI techniques to ensure that the system can explain the decisions. To this end, we used local interpretable model-agnostic explanations and Shapley additive explanations, and we evaluated their differing characteristics. We proposed our explanation framework that consists of the variable importance plot, individual value plot, and partial dependence plot. Furthermore, we conclude by discussing future issues regarding better explainable IDS.
引用
收藏
页码:37 / 42
页数:6
相关论文
共 50 条
  • [21] A hybrid behavioural-based cyber intrusion detection system
    Adhanom, Alemtsehay
    Melaku, Henock M.
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2019, 23 (04) : 473 - 498
  • [22] Complex Event Processing based Hybrid Intrusion Detection System
    Mohan, Ranjan
    Vaidehi, V.
    Krishna, Ajay A.
    Mahalakshmi, M.
    Chakkaravarthy, S. Sibi
    2015 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATION AND NETWORKING (ICSCN), 2015,
  • [23] An Efficient Hybrid Classifier Model for Anomaly Intrusion Detection System
    Shah, Asghar Ali
    Ehsan, M. Khurram
    Ishaq, Kashif
    Ali, Zakir
    Farooq, Muhammad Shoaib
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2018, 18 (11): : 127 - +
  • [24] An Intrusion Detection System over the IoT Data Streams Using eXplainable Artificial Intelligence (XAI)
    Alabbadi, Adel
    Bajaber, Fuad
    SENSORS, 2025, 25 (03)
  • [25] Intrusion Detection System (IDS): Anomaly Detection using Outlier Detection Approach
    Jabez, J.
    Muthukumar, B.
    INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION AND CONVERGENCE (ICCC 2015), 2015, 48 : 338 - 346
  • [26] DeepShield: A Hybrid Deep Learning Approach for Effective Network Intrusion Detection
    Lin, Hongjie
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (07) : 1094 - 1104
  • [27] Distributed Network Intrusion Detection System: An Artificial Immune System Approach
    Igbe, Obinna
    Darwish, Ihab
    Saadawi, Tarek
    2016 IEEE FIRST INTERNATIONAL CONFERENCE ON CONNECTED HEALTH: APPLICATIONS, SYSTEMS AND ENGINEERING TECHNOLOGIES (CHASE), 2016, : 101 - 106
  • [28] Hybrid approach to intrusion detection in fog-based IoT environments
    de Souza, Cristiano Antonio
    Westphall, Carlos Becker
    Machado, Renato Bobsin
    Mangueira Sobral, Joao Bosco
    Vieira, Gustavo dos Santos
    COMPUTER NETWORKS, 2020, 180 (180)
  • [29] RESEARCH AND IMPLEMENTATION ON SNORT-BASED HYBRID INTRUSION DETECTION SYSTEM
    Ding, Yu-Xin
    Xiao, Min
    Liu, Ai-Wu
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6, 2009, : 1414 - 1418
  • [30] A Different Approach of Intrusion Detection and Response System for Relational Databases
    Parmar, Jitendra
    Jain, Pranita
    2013 INTERNATIONAL CONFERENCE ON GREEN COMPUTING, COMMUNICATION AND CONSERVATION OF ENERGY (ICGCE), 2013, : 894 - 899