SIGMA : Strengthening IDS with GAN and Metaheuristics Attacks

SIGMA : Strengthening IDS with GAN and Metaheuristics Attacks
复制标题

SIGMA:利用 GAN 和元启发式攻击强化 IDS

DOI:
--
复制
发表时间:
2019
期刊:
arXiv.org
影响因子:
--
通讯作者:
Foutse Khomh
Foutse Khomh
中科院分区:
--
文献类型:
--
作者:
Simon Msika;A. Quintero;Foutse Khomh

文献摘要

被引文献

相似文献

入侵检测系统(IDS)是网络管理员识别恶意流量和网络攻击的关键网络安全工具。随着最近深度学习等机器学习技术的成功,越来越多的IDS正在使用机器学习算法来更快地检测攻击。然而,当面对以前看不见的攻击类型时,这些系统缺乏健壮性。随着越来越多的新攻击,特别是针对物联网设备的攻击,拥有一个能够发现异常和新攻击的强大IDS变得非常必要。
An Intrusion Detection System (IDS) is a key cybersecurity tool for network administrators as it identifies malicious traffic and cyberattacks. With the recent successes of machine learning techniques such as deep learning, more and more IDS are now using machine learning algorithms to detect attacks faster. However, these systems lack robustness when facing previously unseen types of attacks. With the increasing number of new attacks, especially against Internet of Things devices, having a robust IDS able to spot unusual and new attacks becomes necessary. This work explores the possibility of leveraging generative adversarial models to improve the robustness of machine learning based IDS. More specifically, we propose a new method named SIGMA, that leverages adversarial examples to strengthen IDS against new types of attacks. Using Generative Adversarial Networks (GAN) and metaheuristics, SIGMA %Our method consists in generates adversarial examples, iteratively, and uses it to retrain a machine learning-based IDS, until a convergence of the detection rate (i.e. until the detection system is not improving anymore). A round of improvement consists of a generative phase, in which we use GANs and metaheuristics to generate instances ; an evaluation phase in which we calculate the detection rate of those newly generated attacks ; and a training phase, in which we train the IDS with those attacks. We have evaluated the SIGMA method for four standard machine learning classification algorithms acting as IDS, with a combination of GAN and a hybrid local-search and genetic algorithm, to generate new datasets of attacks. Our results show that SIGMA can successfully generate adversarial attacks against different machine learning based IDS. Also, using SIGMA, we can improve the performance of an IDS to up to 100\% after as little as two rounds of improvement.