xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses

xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Feng Wei;Hongda Li;Ziming Zhao;Hongxin Hu
Feng Wei;Hongda Li;Ziming Zhao;Hongxin Hu
中科院分区:
其他
文献类型:
--
作者:
Feng Wei;Hongda Li;Ziming Zhao;Hongxin Hu

文献摘要

相似文献

虽然基于深度学习的网络入侵检测系统(DL - NIDS)近年来得到了大量的研究,并显示出优越的性能,但由于其检测结果与可操作的解释之间存在语义鸿沟,它们不足以对检测到的入侵做出积极响应。此外,它们的高错误成本使得网络运营商不愿意仅仅基于其检测结果做出响应。这些缺陷的根本原因可追溯到DL - NIDS缺乏可解释性。尽管已经开发了一些方法来解释基于深度学习的系统,但它们无法处理结构化数据的历史输入和复杂的特征依赖关系,并且在解释DL - NIDS方面表现不佳。在本文中,我们提出了X NIDS,这是一种通过解释DL - NIDS来促进主动入侵响应的新颖框架。我们的解释方法具有以下特点:(1)对历史输入进行近似和采样;(2)捕捉结构化数据的特征依赖关系以实现高保真解释。基于解释结果,X NIDS可以进一步生成可操作的防御规则。我们使用四种最先进的DL - NIDS对X NIDS进行了评估。我们的评估结果表明,X NIDS在保真度、稀疏性、完整性和稳定性方面优于以前的解释方法,所有这些对于主动入侵响应都很重要。此外,我们证明了X NIDS能够有效地生成实用的防御规则,有助于理解DL - NIDS的行为,并对检测错误进行排查。
While Deep Learning-based Network Intrusion Detection Systems (DL-NIDS) have recently been significantly explored and shown superior performance, they are insufficient to actively respond to the detected intrusions due to the semantic gap between their detection results and actionable interpretations. Furthermore, their high error costs make network operators unwilling to respond solely based on their detection results. The root cause of these drawbacks can be traced to the lack of explainability of DL-NIDS. Although some methods have been developed to explain deep learning-based systems, they are incapable of handling the history inputs and complex feature dependencies of structured data and do not perform well in explaining DL-NIDS. In this paper, we present X NIDS, a novel framework that facilitates active intrusion responses by explaining DL-NIDS. Our explanation method is highlighted by: (1) approximating and sampling around history inputs; and (2) capturing feature dependencies of structured data to achieve a high-fidelity explanation. Based on the explanation results, X NIDS can further generate actionable defense rules. We evaluate X NIDS with four state-of-the-art DL-NIDS. Our evaluation results show that X NIDS outperforms previous explanation methods in terms of fidelity, sparsity, completeness, and stability, all of which are important to active intrusion responses. Moreover, we demonstrate that X NIDS can efficiently generate practical defense rules, help understand DL-NIDS behaviors, and troubleshoot detection errors.