Improving Attack Detection Performance in NIDS Using GAN
Improving Attack Detection Performance in NIDS Using GAN
复制标题
DOI:
10.1109/compsac48688.2020.0-162
复制
发表时间:
2020-07
期刊:
影响因子:
--
通讯作者:
Dongyang Li;Daisuke Kotani;Y. Okabe
中科院分区:
文献类型:
--
作者:
Dongyang Li;Daisuke Kotani;Y. Okabe
Nowadays, various methods are proposed to build effective anomaly-based Network Intrusion Detection System (NIDS). However, malicious packets are extremely less than normal packets and this class imbalance problem will result in low performance of attack detection. In this study, we have proposed a new hybrid oversampling model using GAN to improve attack detection performance in anomaly-based NIDS. It contains three main steps: feature extraction by Information Gain and PCA, data clustering by DBSCAN and data generation by WGAN-DIV. For performance evaluation, three HTTP only datasets: NSL-KDD-HTTP, UNSW-NB15-HTTP and Kyoto2006-Plus-HTTP are used. Six machine learning methods are utilized as anomaly-based NIDS and SMOTE is also used for comparison. Our model with XGBoost has achieved best F1-score in these three datasets from the results.