Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection

被引:459
|
作者
Mirsky, Yisroel [1 ]
Doitshman, Tomer [1 ]
Elovici, Yuval [1 ]
Shabtai, Asaf [1 ]
机构
[1] Ben Gurion Univ Negev, Beer Sheva, Israel
来源
25TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2018) | 2018年
关键词
Anomaly detection; network intrusion detection; online algorithms; autoencoders; ensemble learning; MACHINE;
D O I
10.14722/ndss.2018.23204
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Neural networks have become an increasingly popular solution for network intrusion detection systems (NIDS). Their capability of learning complex patterns and behaviors make them a suitable solution for differentiating between normal traffic and network attacks. However, a drawback of neural networks is the amount of resources needed to train them. Many network gateways and routers devices, which could potentially host an NIDS, simply do not have the memory or processing power to train and sometimes even execute such models. More importantly, the existing neural network solutions are trained in a supervised manner. Meaning that an expert must label the network traffic and update the model manually from time to time. In this paper, we present Kitsune: a plug and play NIDS which can learn to detect attacks on the local network, without supervision, and in an efficient online manner. Kitsune's core algorithm (KitNET) uses an ensemble of neural networks called autoencoders to collectively differentiate between normal and abnormal traffic patterns. KitNET is supported by a feature extraction framework which efficiently tracks the patterns of every network channel. Our evaluations show that Kitsune can detect various attacks with a performance comparable to offline anomaly detectors, even on a Raspberry PI. This demonstrates that Kitsune can be a practical and economic NIDS.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Analysis of Autoencoders for Network Intrusion Detection
    Song, Youngrok
    Hyun, Sangwon
    Cheong, Yun-Gyung
    SENSORS, 2021, 21 (13)
  • [2] Toward an Online Network Intrusion Detection System Based on Ensemble Learning
    Hsu, Ying-Feng
    He, ZhenYu
    Tarutani, Yuya
    Matsuoka, Morito
    2019 IEEE 12TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (IEEE CLOUD 2019), 2019, : 174 - 178
  • [3] Network Intrusion Detection in Internet of Blended Environment Using Ensemble of Heterogeneous Autoencoders (E-HAE)
    Jilcha L.A.
    Kim D.-H.
    Jang-Jaccard J.
    Kwak J.
    Computer Systems Science and Engineering, 2023, 46 (03): : 3261 - 3284
  • [4] Network Intrusion Detection through Stacking Dilated Convolutional Autoencoders
    Yu, Yang
    Long, Jun
    Cai, Zhiping
    SECURITY AND COMMUNICATION NETWORKS, 2017,
  • [5] Adaptive ensembles of autoencoders for unsupervised IoT network intrusion detection
    Abdul Jabbar Siddiqui
    Azzedine Boukerche
    Computing, 2021, 103 : 1209 - 1232
  • [6] Adaptive ensembles of autoencoders for unsupervised IoT network intrusion detection
    Siddiqui, Abdul Jabbar
    Boukerche, Azzedine
    COMPUTING, 2021, 103 (06) : 1209 - 1232
  • [7] APPLYING A NEURAL NETWORK ENSEMBLE TO INTRUSION DETECTION
    Ludwig, Simone A.
    JOURNAL OF ARTIFICIAL INTELLIGENCE AND SOFT COMPUTING RESEARCH, 2019, 9 (03) : 177 - 188
  • [8] Ensemble Classifiers for Network Intrusion Detection System
    Zainal, Anazida
    Maarof, Mohd Aizaini
    Shamsuddin, Siti Mariyam
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2009, 4 (03): : 217 - 225
  • [9] Anomaly based Resilient Network Intrusion Detection using Inferential Autoencoders
    Hannan, Abdul
    Gruhl, Christian
    Sick, Bernhard
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 1 - 7
  • [10] Unsupervised learning approach for network intrusion detection system using autoencoders
    Hyunseung Choi
    Mintae Kim
    Gyubok Lee
    Wooju Kim
    The Journal of Supercomputing, 2019, 75 : 5597 - 5621