The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems

news/2024/11/9 1:59:14

本文提出了交叉检验的框架,指的是在不同的数据集进行交叉验证。we endorse the idea of cross-evaluating ML-NIDS by using malicious samples captured in different network datasets.1 By performing such cross-evaluations, it is possible to gauge additional
properties of ML-NIDS, allowing a better understanding of
the state-of-the-art at no extra labelling cost.

However, most related work simply used such data as an ‘additional’ setting to perform their experiments. In contrast, in this paper we promote a different approach, based on mixing different network data to cross-evaluate ML-NIDS

链接为:https://arxiv.org/abs/2203.04686

异常检测是发现真实入侵攻击的辅助工作

Specificallyin NID, by creating a training dataset where the samples are distinguished between benign and malicious, it is possible to
develop a fully autonomous Machine Learning-based Network
Intrusion Detection System (ML-NIDS)

Abstract—Enhancing Network Intrusion Detection Systems
(NIDS) with supervised Machine Learning (ML) is tough. MLNIDS must be trained and evaluated, operations requiring data where benign and malicious samples are clearly labelled.

Such labels demand costly expert knowledge, resulting in a lack of real deployments, as well as on papers always relying on the same
outdated data. The situation improved recently, as some efforts
disclosed their labelled datasets. However, most past works used
such datasets just as a ‘yet another’ testbed, overlooking the
added potential provided by such availability.

In contrast, we promote using such existing labelled data to
cross-evaluate ML-NIDS. Such approach received only limited attention and, due to its complexity, requires a dedicated treatment.
We hence propose the first cross-evaluation model. Our model
highlights the broader range of realistic use-cases that can be
assessed via cross-evaluations, allowing the discovery of still unknown qualities of state-of-the-art ML-NIDS. For instance, their
detection surface can be extended—at no additional labelling
cost. However, conducting such cross-evaluations is challenging.
Hence, we propose the first framework, XeNIDS, for reliable
cross-evaluations based on Network Flows. By using XeNIDS on
six well-known datasets, we demonstrate the concealed potential,
but also the risks, of cross-evaluations of ML-NIDS.


http://www.niftyadmin.cn/n/4230174.html

相关文章

图神经网络在反欺诈领域的应用

具体场景为图神经网络在恶意网址检测中的应用。 文章目录1. 场景介绍2. 节点刻画3. 恶意网址检测3.1 构建图3.2 模型设计3.3 评估结果1. 场景介绍 恶意网址检测中存在的难点有两方面: 一是借助短链接或跳转的方式到恶意网址,链接或跳转的前置页面特征不…

创造选择与选择权

当我发烧时,其实并不是我们发烧,而是被发烧所控制。同理,当我们变富后,也会被富裕所控制。These individuals have riches just as we say that we “have a fever,” when really the fever has us. I also have in mind that s…

用Markdown画流程图

流程图语法: 流程图的语法大体分为两部分:流程图元素定义部分;连接流程图元素部分,该部分用来指明流程图的执行走向。 定义元素的语法 tag>type: content:>url 实例: flowchat st>start: 开始 e>end: …

Burp Suite详细教程

文章目录1. Proxy模块2. Send to Intruder3. Repeater1. Proxy模块 抓包之前必须配置代理服务器,将代理IP设置为127.0.0.1,Chrome如下图所示 在Burp Suite中 使intercept is on 打开拦截: 在浏览器中打开页面,就能在软件中查看相…

复盘概念解释

复盘,围棋术语,也称 “复局”,指对局完毕后,复演该盘棋的记录,以检查对局中招法的优劣与得失关键。一般用以自学,或请高手给予指导分析。如按照棋谱排演,类如复盘,称 “ 打谱 ” 或 …

神经网络概念解释

人工神经网络(Artificial Neural Networks,简写为ANNs)也简称为神经网络(NNs)或称作连接模型(Connection Model),它是一种模仿动物神经网络行为特征,进行分布式并行信息处…

机器学习概念解释

机器学习是一门多领域交叉学科,涉及概率论、统计学、逼近论、凸分析、算法复杂度理论等多门学科。专门研究计算机怎样模拟或实现人类的学习行为,以获取新的知识或技能,重新组织已有的知识结构使之不断改善自身的性能。它是人工智能核心&#…

有关复盘的阅读与思考

先说下读完复盘两本书的感受吧,读完后突然有一种若干年前上考研学习班的感觉,同样一门课不同的老师讲解,貌似学到了越来越多的知识,但是好像什么也没有学到。然后先谈谈自己对复盘的新思考吧,复盘本质上是源自于围棋&a…