학술논문

DOC-NAD: A Hybrid Deep One-class Classifier for Network Anomaly Detection
Document Type
Conference
Source
2023 IEEE/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW) CCGRIDW Cluster, Cloud and Internet Computing Workshops (CCGridW), 2023 IEEE/ACM 23rd International Symposium on. :1-7 May, 2023
Subject
Computing and Processing
Training
Histograms
Network intrusion detection
Machine learning
Feature extraction
Security
Reliability
One-class classifier
intrusion detection
machine learning
anomaly detection
Language
Abstract
Machine Learning (ML) approaches have been used to enhance the detection capabilities of Network Intrusion Detection Systems (NIDSs). Recent work has achieved near-perfect performance by following binary- and multi-class network anomaly detection tasks. Such systems depend on the availability of both (benign and malicious) network data classes during the training phase. However, attack data samples are often challenging to collect in most organisations due to security controls preventing the penetration of known malicious traffic to their networks. Therefore, this paper proposes a Deep One-Class (DOC) classifier for network intrusion detection by only training on benign network data samples. The novel one-class classification architecture consists of a histogram-based deep feed-forward classifier to extract useful network data features and use efficient outlier detection. The DOC classifier has been extensively evaluated using two benchmark NIDS datasets. The results demonstrate its superiority over current state-of-the-art one-class classifiers in terms of detection and false positive rates.