We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Collaborative Feature Maps of Networks and Hosts for AI-driven Intrusion Detection

Abstract: Intrusion Detection Systems (IDS) are critical security mechanisms that protect against a wide variety of network threats and malicious behaviors on networks or hosts. As both Network-based IDS (NIDS) or Host-based IDS (HIDS) have been widely investigated, this paper aims to present a Combined Intrusion Detection System (CIDS) that integrates network and host data in order to improve IDS performance. Due to the scarcity of datasets that include both network packet and host data, we present a novel CIDS dataset formation framework that can handle log files from a variety of operating systems and align log entities with network flows. A new CIDS dataset named SCVIC-CIDS-2021 is derived from the meta-data from the well-known benchmark dataset, CIC-IDS-2018 by utilizing the proposed framework. Furthermore, a transformer-based deep learning model named CIDS-Net is proposed that can take network flow and host features as inputs and outperform baseline models that rely on network flow features only. Experimental results to evaluate the proposed CIDS-Net under the SCVIC-CIDS-2021 dataset support the hypothesis for the benefits of combining host and flow features as the proposed CIDS-Net can improve the macro F1 score of baseline solutions by 6.36% (up to 99.89%).
Comments: IEEE Global Communications Conference (Globecom), 2022, 6 pages, 3 figures 4 tables
Subjects: Cryptography and Security (cs.CR)
DOI: 10.1109/GLOBECOM48099.2022.10000985
Cite as: arXiv:2208.05085 [cs.CR]
  (or arXiv:2208.05085v1 [cs.CR] for this version)

Submission history

From: Burak Kantarci [view email]
[v1] Wed, 10 Aug 2022 00:16:49 GMT (3593kb)

Link back to: arXiv, form interface, contact.