3.8 Proceedings Paper

On the use of Machine Learning Approaches for the Early Classification in Network Intrusion Detection

出版社

IEEE
DOI: 10.1109/MN55117.2022.9887775

关键词

Network intrusion detection; Security; Machine learning; CSE-CIC-IDS2018; Early detection

向作者/读者索取更多资源

Current intrusion detection techniques are incapable of dealing with the growing quantity and complexity of cyber attacks. Machine Learning techniques have been proposed for postmortem detection of network attacks, with many datasets available for training and validation purposes. This paper presents an early classification approach using CSE-CIC-IDS2018 dataset to detect malicious attacks before they can cause harm to an organization, by investigating a different set of features and analyzing the sensitivity of five classification algorithms to the number of observed packets. Results indicate that satisfactory results can be achieved with ML approaches relying on only ten packets.
Current intrusion detection techniques cannot keep up with the increasing amount and complexity of cyber attacks. In fact, most of the traffic is encrypted and does not allow to apply deep packet inspection approaches. In recent years, Machine Learning techniques have been proposed for postmortem detection of network attacks, and many datasets have been shared by research groups and organizations for training and validation. Differently from the vast related literature, in this paper we propose an early classification approach conducted on CSE-CIC-IDS2018 dataset, which contains both benign and malicious traffic, for the detection of malicious attacks before they could damage an organization. To this aim, we investigated a different set of features, and the sensitivity of performance of five classification algorithms to the number of observed packets. Results show that ML approaches relying on ten packets provide satisfactory results.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据