Improving Attack Detection Performance in NIDS Using GAN

Improving Attack Detection Performance in NIDS Using GAN
复制标题

DOI:
10.1109/compsac48688.2020.0-162
复制
发表时间:
2020-07
期刊:
2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC)
影响因子:
--
通讯作者:
Dongyang Li;Daisuke Kotani;Y. Okabe
Dongyang Li;Daisuke Kotani;Y. Okabe
中科院分区:
其他
文献类型:
--
作者:
Dongyang Li;Daisuke Kotani;Y. Okabe

文献摘要

相似文献

如今,人们提出了各种方法来构建有效的基于异常的网络入侵检测系统(NIDS)。然而,恶意数据包远少于正常数据包,这种类别不平衡问题将导致攻击检测性能低下。在这项研究中,我们提出了一种使用 GAN 的新混合过采样模型,以提高基于异常的 NIDS 中的攻击检测性能。它包含三个主要步骤:通过信息增益和PCA进行特征提取、通过DBSCAN进行数据聚类以及通过WGAN-DIV进行数据生成。为了进行性能评估,使用了三个仅 HTTP 数据集:NSL-KDD-HTTP、UNSW-NB15-HTTP 和京都2006-Plus-HTTP。采用六种机器学习方法作为基于异常的 NIDS,并使用 SMOTE 进行比较。从结果来看,我们使用 XGBoost 的模型在这三个数据集中取得了最佳 F1 分数。
Nowadays, various methods are proposed to build effective anomaly-based Network Intrusion Detection System (NIDS). However, malicious packets are extremely less than normal packets and this class imbalance problem will result in low performance of attack detection. In this study, we have proposed a new hybrid oversampling model using GAN to improve attack detection performance in anomaly-based NIDS. It contains three main steps: feature extraction by Information Gain and PCA, data clustering by DBSCAN and data generation by WGAN-DIV. For performance evaluation, three HTTP only datasets: NSL-KDD-HTTP, UNSW-NB15-HTTP and Kyoto2006-Plus-HTTP are used. Six machine learning methods are utilized as anomaly-based NIDS and SMOTE is also used for comparison. Our model with XGBoost has achieved best F1-score in these three datasets from the results.