Network intrusion detection based on the temporal convolutional model

被引:27
作者
Lopes, Ivandro O. [1 ,2 ,3 ,4 ]
Zou, Deqing [1 ,3 ,5 ,9 ,10 ]
Abdulqadder, Ihsan H. [6 ]
Akbar, Saeed [7 ]
Li, Zhen [1 ,3 ,5 ]
Ruambo, Francis [1 ,2 ,3 ,8 ]
Pereira, Wagner
机构
[1] Huazhong Univ Sci & Technol, Sch Cyber Sci & Engn, Wuhan 430074, Peoples R China
[2] Natl Engn Res Ctr Big Data Technol & Syst, Wuhan, Peoples R China
[3] Cluster & Grid Comp Lab, Wuhan, Peoples R China
[4] Serv Comp Technol & Syst Lab, Wuhan, Peoples R China
[5] Nucleo Operac Soc Informacao, Praia, Cape Verde
[6] Big Data Secur Engn Res Ctr, Wuhan, Peoples R China
[7] Kirkuk Univ, Dept Comp Sci, Kirkuk, Iraq
[8] Zhejiang Normal Univ, Sch Comp Sci & Technol, Jinhua, Peoples R China
[9] Huazhong Univ Sci & Technol, Sch Comp Sci & Technol, Wuhan 430074, Peoples R China
[10] Huazhong Univ Sci & Technol, Wuhan, Peoples R China
关键词
Cyber security; Network intrusion detection; Deep learning; Time series classification; Temporal convolutional model;
D O I
10.1016/j.cose.2023.103465
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recurrent networks have been adopted as default architecture in approaches performing sequence modelling of network intrusion detection problems. However, models based on Recurrent Neural Network (RNN) architecture have some limitations regarding computation complexity and detection performance due to information loss. Recent studies suggested that certain convolutional-based architectures that can natively process temporal data outperform recurrent networks in time series modelling, such as speech synthesis and machine translation. Inspired by the success of temporal-based convolutional architectures in other domains, this paper designs and implements four temporal-based convolutional models in network intrusion detection and studies their classification performance. The models are based on MINImally RandOm Convolutional KErnel Transform (MiniRocket), eXplainable Convolutional Neural Network for Multivariate Time Series Classification (XCM), One-Dimensional Convolution Neural Network (OS-CNN), and Time Series Transformer (TST) architecture. We evaluate our models using the effectiveness and efficiency metrics based on CICDDoS2019 and CSE-CIC-IDS2018 datasets. Every model has achieved a high evaluation performance in the range between 98.07% and 99.99% in most considered metrics using the test dataset. MiniRocket and OS-CNN obtained the highest evaluation results regarding the effectiveness metrics. The high evaluation results suggest that they can improve the detection effectiveness of approaches formulating network intrusion detection as a time series task.
引用
收藏
页数:17
相关论文
共 65 条
[1]   Multi-layered intrusion detection and prevention in the SDN/NFV enabled cloud of 5G networks using AI-based defense mechanisms [J].
Abdulqadder, Ihsan H. ;
Zhou, Shijie ;
Zou, Deqing ;
Aziz, Israa T. ;
Akber, Syed Muhammad Abrar .
COMPUTER NETWORKS, 2020, 179
[2]   Anomaly Detection Using Deep Neural Network for IoT Architecture [J].
Ahmad, Zeeshan ;
Khan, Adnan Shahid ;
Nisar, Kashif ;
Haider, Iram ;
Hassan, Rosilah ;
Haque, Muhammad Reazul ;
Tarmizi, Seleviawati ;
Rodrigues, Joel J. P. C. .
APPLIED SCIENCES-BASEL, 2021, 11 (15)
[3]   Experimental Evaluation of a Multi-Layer Feed-Forward Artificial Neural Network Classifier for Network Intrusion Detection System [J].
Al-Zewairi, Malek ;
Almajali, Sufyan ;
Awajan, Arafat .
2017 INTERNATIONAL CONFERENCE ON NEW TRENDS IN COMPUTING SCIENCES (ICTCS), 2017, :167-172
[4]   Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues [J].
Aldweesh, Arwa ;
Derhab, Abdelouahid ;
Emam, Ahmed Z. .
KNOWLEDGE-BASED SYSTEMS, 2020, 189
[5]  
[Anonymous], 2017, CoRR
[6]   GRU-based deep learning approach for network intrusion alert prediction [J].
Ansari, Mohammad Samar ;
Bartos, Vaclav ;
Lee, Brian .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 128 :235-247
[7]   A GRU deep learning system against attacks in software defined networks [J].
Assis, Marcos V. O. ;
Carvalho, Luiz F. ;
Lloret, Jaime ;
Proenca, Mario L. .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 177
[8]   The great time series classification bake off: a review and experimental evaluation of recent algorithmic advances [J].
Bagnall, Anthony ;
Lines, Jason ;
Bostrom, Aaron ;
Large, James ;
Keogh, Eamonn .
DATA MINING AND KNOWLEDGE DISCOVERY, 2017, 31 (03) :606-660
[9]  
Bai S., 2018, CoRR
[10]  
Bastola S.B., 2021, Distributed denial of service attack detection on software defined networking using deep learning