4.6 Article

Consolidating Packet-Level Features for Effective Network Intrusion Detection: A Novel Session-Level Approach

Journal

IEEE ACCESS
Volume 11, Issue -, Pages 132792-132810

Publisher

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/ACCESS.2023.3335600

Keywords

Feature extraction; Payloads; Network intrusion detection; Benchmark testing; Telecommunication traffic; Real-time systems; Prototypes; Network security; Machine learning; network intrusion detection; network traffic analysis; machine learning

Ask authors/readers for more resources

This study proposes a session-level classification approach that consolidates packet-level classification outputs to identify anomalous sessions. Experimental results demonstrate the high performance and efficiency of this approach.
Network Intrusion Detection Systems (NIDSs) are crucial tools for ensuring cyber security. Recently, machine learning-based NIDSs have gained popularity due to their ability to adapt to various anomalies. To enable machine learning techniques, packet-level features have been proposed for packet-level classification, but this approach may generate an excessive number of security alerts and reduce performance due to irrelevant packets. To address these limitations, this paper proposes a session-level classification approach that consolidates packet-level classification outputs to identify anomalous sessions. The effectiveness of the proposed approach is demonstrated by a prototype system. Experiments on a publicly available benchmark dataset demonstrate the high performance of proposed approach achieving F1-measure exceeding 98%. It also shows that even when we used only a few packets in head parts of each session to obtain session-level predictions, the high F1-measure still could be achieved. This result implies that the proposed approach is also efficient in terms of the number of packets to be processed. These results highlight the promising potential of the proposed approach for adaptive network intrusion detection.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available