Evolving deep learning architectures for network intrusion detection using a double PSO metaheuristic

被引:156
作者
Elmasry, Wisam [1 ]
Akbulut, Akhan [2 ]
Zaim, Abdul Halim [1 ]
机构
[1] Istanbul Commerce Univ, Dept Comp Engn, TR-34840 Istanbul, Turkey
[2] Istanbul Kultur Univ, Dept Comp Engn, TR-34158 Istanbul, Turkey
关键词
Cyber security; Deep learning; Feature selection; Hyperparameter selection; Network intrusion detection; Particle swarm optimization; PARTICLE SWARM OPTIMIZATION; FEATURE-SELECTION; GENETIC ALGORITHMS; NEURAL-NETWORKS; CLASSIFIERS;
D O I
10.1016/j.comnet.2019.107042
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The prevention of intrusion is deemed to be a cornerstone of network security. Although excessive work has been introduced on network intrusion detection in the last decade, finding an Intrusion Detection Systems (IDS) with potent intrusion detection mechanism is still highly desirable. One of the leading causes of the high number of false alarms and a low detection rate is the existence of redundant and irrelevant features of the datasets, which are used to train the 1DSs. To cope with this problem, we proposed a double Particle Swarm Optimization (PSO)-based algorithm to select both feature subset and hyperparameters in one process. The aforementioned algorithm is exploited in the pre-training phase for selecting the optimized features and model's hyperparameters automatically. In order to investigate the performance differences, we utilized three deep learning models, namely, Deep Neural Networks (DNN), Long Short-Term Memory Recurrent Neural Networks (LSTM-RNN), and Deep Belief Networks (DBN). Furthermore, we used two common IDS datasets in our experiments to validate our approach and show the effectiveness of the developed models. Moreover, many evaluation metrics are used for both binary and multiclass classifications to assess the model's performance in each of the datasets. Finally, intensive quantitative, Friedman test, and ranking methods analyses of our results are provided at the end of this paper. Experimental results show a significant improvement in network intrusion detection when using our approach by increasing Detection Rate (DR) by 4% to 6% and reducing False Alarm Rate (FAR) by 1% to 5% from the corresponding values of same models without pre-training on the same dataset. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页数:21
相关论文
共 109 条
  • [61] Landgrebe TCW, 2006, INT C PATT RECOG, P123
  • [62] LANGLEY P, 1994, P AAAI FALL S REL, P1
  • [63] Liangjun Ke, 2010, 2010 Second Pacific-Asia Conference on Circuits,Communications and System (PACCS 2010), P207, DOI 10.1109/PACCS.2010.5627071
  • [64] Particle swarm optimization for parameter determination and feature selection of support vector machines
    Lin, Shih-Wei
    Ying, Kuo-Ching
    Chen, Shih-Chieh
    Lee, Zne-Jung
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2008, 35 (04) : 1817 - 1824
  • [65] Intrusion detection based on IDBM
    Liu, Yajun
    Zhang, Xuan
    [J]. 2016 IEEE 14TH INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, 14TH INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, 2ND INTL CONF ON BIG DATA INTELLIGENCE AND COMPUTING AND CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/DATACOM/CYBERSC, 2016, : 173 - 177
  • [66] Particle Swarm Optimization for Hyper-Parameter Selection in Deep Neural Networks
    Lorenzo, Pablo Ribalta
    Nalepa, Jakub
    Kawulok, Michal
    Sanchez Ramos, Luciano
    Ranilla Pastor, Jose
    [J]. PROCEEDINGS OF THE 2017 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE (GECCO'17), 2017, : 481 - 488
  • [67] Hyper-Parameter Selection in Deep Neural Networks Using Parallel Particle Swarm Optimization
    Lorenzo, Pablo Ribalta
    Nalepa, Jakub
    Sanchez Ramos, Luciano
    Ranilla Pastor, Jose
    [J]. PROCEEDINGS OF THE 2017 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE COMPANION (GECCO'17 COMPANION), 2017, : 1864 - 1871
  • [68] Ludwig SA, 2017, 2017 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), P541
  • [69] Mahmood T, 2013, 2013 2ND NATIONAL CONFERENCE ON INFORMATION ASSURANCE (NCIA), P129, DOI 10.1109/NCIA.2013.6725337
  • [70] Distributed Abnormal Behavior Detection Approach Based on Deep Belief Network and Ensemble SVM Using Spark
    Marir, Naila
    Wang, Huiqiang
    Feng, Guangsheng
    Li, Bingyang
    Jia, Meijuan
    [J]. IEEE ACCESS, 2018, 6 : 59657 - 59671