Towards a Reliable Comparison and Evaluation of Network Intrusion Detection Systems Based on Machine Learning Approaches

被引:68
作者
Magan-Carrion, Roberto [1 ]
Urda, Daniel [2 ]
Diaz-Cano, Ignacio [3 ]
Dorronsoro, Bernabe [1 ]
机构
[1] Univ Cadiz, Sch Engn, Dept Comp Sci & Engn, Cadiz 11519, Spain
[2] Univ Burgos, Sch Engn, Dept Comp Engn, Burgos 09006, Spain
[3] Univ Cadiz, Sch Engn, Dept Automat Elect Comp Architecture & Commun Net, Cadiz 11519, Spain
来源
APPLIED SCIENCES-BASEL | 2020年 / 10卷 / 05期
关键词
network intrusion detection; NIDS; machine learning; attack detection; communications networks; methodology; DATASET;
D O I
10.3390/app10051775
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Presently, we are living in a hyper-connected world where millions of heterogeneous devices are continuously sharing information in different application contexts for wellness, improving communications, digital businesses, etc. However, the bigger the number of devices and connections are, the higher the risk of security threats in this scenario. To counteract against malicious behaviours and preserve essential security services, Network Intrusion Detection Systems (NIDSs) are the most widely used defence line in communications networks. Nevertheless, there is no standard methodology to evaluate and fairly compare NIDSs. Most of the proposals elude mentioning crucial steps regarding NIDSs validation that make their comparison hard or even impossible. This work firstly includes a comprehensive study of recent NIDSs based on machine learning approaches, concluding that almost all of them do not accomplish with what authors of this paper consider mandatory steps for a reliable comparison and evaluation of NIDSs. Secondly, a structured methodology is proposed and assessed on the UGR'16 dataset to test its suitability for addressing network attack detection problems. The guideline and steps recommended will definitively help the research community to fairly assess NIDSs, although the definitive framework is not a trivial task and, therefore, some extra effort should still be made to improve its understandability and usability further.
引用
收藏
页数:21
相关论文
共 43 条
  • [1] [Anonymous], ENISA Threat Landscape 2022'
  • [2] [Anonymous], P JORN NAC INV CIB C
  • [3] [Anonymous], KDD CUP 1999 DAT
  • [4] [Anonymous], 2019, ARXIV190500304
  • [5] [Anonymous], 2006, Pattern Recognition and Machine Learning
  • [6] [Anonymous], FAAC FEATURE COUNTER
  • [7] [Anonymous], 2012, P 25 INT C NEURIPS
  • [8] [Anonymous], CAM UI 3250CP C HQ
  • [9] [Anonymous], P 2015 MIL COMM INF
  • [10] [Anonymous], INTRUSION DETECTION