On the Evaluation of Sequential Machine Learning for Network Intrusion Detection

06/15/2021
by   Andrea Corsini, et al.
0

Recent advances in deep learning renewed the research interests in machine learning for Network Intrusion Detection Systems (NIDS). Specifically, attention has been given to sequential learning models, due to their ability to extract the temporal characteristics of Network traffic Flows (NetFlows), and use them for NIDS tasks. However, the applications of these sequential models often consist of transferring and adapting methodologies directly from other fields, without an in-depth investigation on how to leverage the specific circumstances of cybersecurity scenarios; moreover, there is a lack of comprehensive studies on sequential models that rely on NetFlow data, which presents significant advantages over traditional full packet captures. We tackle this problem in this paper. We propose a detailed methodology to extract temporal sequences of NetFlows that denote patterns of malicious activities. Then, we apply this methodology to compare the efficacy of sequential learning models against traditional static learning models. In particular, we perform a fair comparison of a `sequential' Long Short-Term Memory (LSTM) against a `static' Feedforward Neural Networks (FNN) in distinct environments represented by two well-known datasets for NIDS: the CICIDS2017 and the CTU13. Our results highlight that LSTM achieves comparable performance to FNN in the CICIDS2017 with over 99.5% F1-score; while obtaining superior performance in the CTU13, with 95.7% F1-score against 91.5%. This paper thus paves the way to future applications of sequential learning models for NIDS.

READ FULL TEXT

page 7

page 9

research
06/13/2023

Intrusion Detection: A Deep Learning Approach

Network intrusions are a significant problem in all industries today. A ...
research
11/26/2019

Network Intrusion Detection based on LSTM and Feature Embedding

Growing number of network devices and services have led to increasing de...
research
02/20/2022

NetSentry: A Deep Learning Approach to Detecting Incipient Large-scale Network Attacks

Machine Learning (ML) techniques are increasingly adopted to tackle ever...
research
05/26/2016

Video Summarization with Long Short-term Memory

We propose a novel supervised learning technique for summarizing videos ...
research
12/26/2020

Predicting Organizational Cybersecurity Risk: A Deep Learning Approach

Cyberattacks conducted by malicious hackers cause irreparable damage to ...
research
02/26/2019

Design of intentional backdoors in sequential models

Recent work has demonstrated robust mechanisms by which attacks can be o...
research
04/04/2023

Multi model LSTM architecture for Track Association based on Automatic Identification System Data

For decades, track association has been a challenging problem in marine ...

Please sign up or login with your details

Forgot password? Click here to reset