A bidirectional LSTM deep learning approach for intrusion detection

被引:214
作者
Imrana, Yakubu [1 ]
Xiang, Yanping [1 ]
Ali, Liaqat [2 ,3 ]
Abdul-Rauf, Zaharawu [4 ]
机构
[1] Univ Elect Sci & Technol China UESTC, Sch Comp Sci & Engn, Chengdu 611731, Peoples R China
[2] Univ Elect Sci & Technol China UESTC, Sch Informat & Commun Engn, Chengdu 611731, Peoples R China
[3] Univ Sci & Technol, Dept Elect Engn, Bannu, Pakistan
[4] Univ Dev Studies UDS, Dept Educ, Tamale, Ghana
关键词
Machine learning; Deep learning; Recurrent neural networks; Bidirectional LSTM; Intrusion detection; ANOMALY DETECTION; NEURAL-NETWORKS;
D O I
10.1016/j.eswa.2021.115524
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The rise in computer networks and internet attacks has become alarming for most service providers. It has triggered the need for the development and implementation of intrusion detection systems (IDSs) to help prevent and or mitigate the challenges posed by network intruders. Over the years, intrusion detection systems have played and continue to play a very significant role in spotting network attacks and anomalies. Numerous researchers around the globe have proposed many IDSs to combat the threat of network invaders. However, most of the previously proposed IDSs have high rates of raising false alarms. Additionally, most existing models suffer the difficulty of detecting the different attack types, especially User-to-Root (U2R) and Remote-to-Local (R2L) attacks. These two types of attacks often appear to have lower detection accuracy for the existing models. Hence, in this paper, we propose a bidirectional Long-Short-Term-Memory (BiDLSTM) based intrusion detection system to handle the challenges mentioned above. To train and measure our model's performance, we use the NSL-KDD dataset, a benchmark dataset for most IDSs. Experimental results show and validate the effectiveness of the BiDLSTM approach. It outperforms conventional LSTM and other state-of-the-art models in terms of accuracy, precision, recall, and F-score values. It also has a much more reduced false alarm rate than the existing models. Furthermore, the BiDLSTM model achieves a higher detection accuracy for U2R and R2L attacks than the conventional LSTM.
引用
收藏
页数:12
相关论文
共 48 条
[1]   A feature reduced intrusion detection system using ANN classifier [J].
Akashdeep ;
Manzoor, Ishfaq ;
Kumar, Neeraj .
EXPERT SYSTEMS WITH APPLICATIONS, 2017, 88 :249-257
[2]   Early diagnosis of Parkinson's disease from multiple voice recordings by simultaneous sample and feature selection [J].
Ali, Liaqat ;
Zhu, Ce ;
Zhou, Mingyi ;
Liu, Yipeng .
EXPERT SYSTEMS WITH APPLICATIONS, 2019, 137 :22-28
[3]  
[Anonymous], 1998, National Information Systems Security Conference
[4]   Deep learning [J].
LeCun, Yann ;
Bengio, Yoshua ;
Hinton, Geoffrey .
NATURE, 2015, 521 (7553) :436-444
[5]   Long short-term memory [J].
Hochreiter, S ;
Schmidhuber, J .
NEURAL COMPUTATION, 1997, 9 (08) :1735-1780
[6]   LEARNING LONG-TERM DEPENDENCIES WITH GRADIENT DESCENT IS DIFFICULT [J].
BENGIO, Y ;
SIMARD, P ;
FRASCONI, P .
IEEE TRANSACTIONS ON NEURAL NETWORKS, 1994, 5 (02) :157-166
[7]   Representation Learning: A Review and New Perspectives [J].
Bengio, Yoshua ;
Courville, Aaron ;
Vincent, Pascal .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2013, 35 (08) :1798-1828
[8]  
Beqiri E, 2009, COMM COM INF SC, V45, P156
[9]   A Survey of Deep Learning Methods for Cyber Security [J].
Berman, Daniel S. ;
Buczak, Anna L. ;
Chavis, Jeffrey S. ;
Corbett, Cherita L. .
INFORMATION, 2019, 10 (04)
[10]   An analysis of "A feature reduced intrusion detection system using ANN classifier" by Akashdeep et al. expert systems with applications (2017) [J].
Chandak, Trupti ;
Shukla, Sanyam ;
Wadhvani, Rajesh .
EXPERT SYSTEMS WITH APPLICATIONS, 2019, 130 :79-83