Examining traffic microstructures to improve model development

Examining traffic microstructures to improve model development
复制标题

DOI:
10.1109/spw53761.2021.00011
复制
发表时间:
2021-05
期刊:
2021 IEEE Security and Privacy Workshops (SPW)
影响因子:
--
通讯作者:
H. Clausen;David Aspinall
H. Clausen;David Aspinall
中科院分区:
其他
文献类型:
--
作者:
H. Clausen;David Aspinall

文献摘要

被引文献

相似文献

我们演示了如何通过使用具有特定控制的微结构的流量来探测模型来验证和开发基于机器学习的网络入侵检测模型。我们通过探索两个已发表的最先进的模型来发现分类缺陷并理解不当行为,从而展示了我们的方法。这些模型不适用于具有特定特征的输入流量,例如重传或过度分散的流到达间隔时间。在做了简单的相应模型修正后,检测率已经提高了2-4%。我们相信,这显示了使用具有可控和标签特征的定制数据来有效改进NID中的模型开发的前景,这种做法在机器学习的其他几个领域帮助了模型开发。
We demonstrate how machine-learning-based network intrusion detection models can be validated and developed by probing models using traffic with specifically controlled microstructures. We show our methodology by probing two published state-of-the-art models to find classification flaws and and understand misbehaviour. These models fail for input traffic with particular characteristics such as retransmissions or overly dispersed flow interarrival times. After we make simple corresponding model corrections, detection rates already improve between 2 -4%. We believe this shows promise for using tailored data with controllable and labelled characteristics to effectively improve model development in NID, a practice that helped model development significantly in several other areas of machinelearning.