Extreme minority class detection in imbalanced data for network intrusion

被引:12
|
作者
Milosevic, Marija S. [1 ]
Ciric, Vladimir M. [1 ]
机构
[1] Univ Nis, Fac Elect Engn, Nish, Serbia
关键词
Network security; Network intrusion detection; Deep learning; Multi-class classification; Feature analysis; CICIDS-2017;
D O I
10.1016/j.cose.2022.102940
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the amount of traffic on the Internet increases, so does the number of new and sophisticated net-work attacks. Intrusion detection systems are the most important tools for accurate detection of potential threats. Due to the dynamic nature of network attacks, deep learning neural networks play a signifi-cant role in intrusion detection, as they have proven to be effective in processing large amounts of data. However, deep learning networks often have difficulties to effectively detect attack classes that are in minority, when trained with imbalanced cybersecurity data. The common way to deal with this difficulty is resampling. In contrast to resampling, in this paper we implement Deep Neural Network for intrusion detection varying its parameters, and analyze detection performances of minority classes in imbalanced multi-class data. The model is trained and tested on the CICIDS-2017 dataset, which contains almost 3 million records and 15 traffic classes, where some classes are in extreme minority, holding only a few records per class. Additionally, the model was evaluated on an also imbalanced CICIDS-2018 dataset. Two feature selection methods are performed on the preprocessed data, in order to obtain two different fea-ture subsets. Our findings show that some coarse grained features are of such significance that attacks with only 3 instances can be completely and accurately detected. As a conclusion, we show the difference in feature characteristics for minority classes that are crucial for their detection. (c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Resampling imbalanced data for network intrusion detection datasets
    Sikha Bagui
    Kunqi Li
    Journal of Big Data, 8
  • [2] Resampling imbalanced data for network intrusion detection datasets
    Bagui, Sikha
    Li, Kunqi
    JOURNAL OF BIG DATA, 2021, 8 (01)
  • [3] Enhancing network based intrusion detection for imbalanced data
    Engen, Vegard
    Vincent, Jonathan
    Phalp, Keith
    INTERNATIONAL JOURNAL OF KNOWLEDGE-BASED AND INTELLIGENT ENGINEERING SYSTEMS, 2008, 12 (5-6) : 357 - 367
  • [4] Dealing with Imbalanced Data in Multi-class Network Intrusion Detection Systems Using XGBoost
    AL-Essa, Malik
    Appice, Annalisa
    MACHINE LEARNING AND PRINCIPLES AND PRACTICE OF KNOWLEDGE DISCOVERY IN DATABASES, PT II, 2021, 1525 : 5 - 21
  • [5] A Deep Learning Model for Network Intrusion Detection with Imbalanced Data
    Fu, Yanfang
    Du, Yishuai
    Cao, Zijian
    Li, Qiang
    Xiang, Wei
    ELECTRONICS, 2022, 11 (06)
  • [6] Addressing Imbalanced Data in Network Intrusion Detection: A Review and Survey
    Al-Qarni, Elham Abdullah
    Al-Asmari, Ghadah Ahmad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (02) : 136 - 143
  • [7] Addressing Imbalanced Data Problem with Generative Adversarial Network For Intrusion Detection
    Yilmaz, Ibrahim
    Masum, Rahat
    Siraj, Ambareen
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2020), 2020, : 25 - 30
  • [8] Improving intrusion detection for imbalanced network traffic
    Thomas, Ciza
    SECURITY AND COMMUNICATION NETWORKS, 2013, 6 (03) : 309 - 324
  • [9] Deep Learning Intrusion Detection Model Based on Optimized Imbalanced Network Data
    Zhang, Yan
    Zhang, Hongmei
    Zhang, Xiangli
    Qi, Dongsheng
    2018 IEEE 18TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2018, : 1128 - 1132
  • [10] An Imbalanced Data Processing Method for Intrusion Detection
    Xu, Yichao
    Zhao, Rui
    Zhang, Wenyue
    2024 5TH INFORMATION COMMUNICATION TECHNOLOGIES CONFERENCE, ICTC 2024, 2024, : 82 - 87