<p>Intrusion Detection Systems (IDS) play a vital role in cybersecurity by identifying and mitigating malicious activities in network traffic. However, the high volume of alerts often leads to false positives, alert fatigue, and missed threats. Conventional IDS methods detect isolated anomalies primarily, but fail to capture temporal and contextual relationships between alerts. To address these limitations, we introduce an IDS model that utilizes transformer-based encoder attention mechanisms. Inspired by advances in natural language processing, our approach dynamically prioritizes alerts based on context, enhancing the detection of critical threats and uncovering hidden attack patterns. This significantly reduces false positives while improving detection accuracy. By carefully tuning the model components such as the number of encoder layers, attention heads, batch size, and feedforward layer size, our model achieved a classification accuracy of 99.34% with an error rate of just 0.55% on the test data. These results highlight the effectiveness of encoder attention mechanisms in optimizing IDS performance, particularly when combined with dense neural layers, demonstrating the potential of Transformer-based models in developing more adaptive and intelligent IDS.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

TBAC-IDS: enhancing intrusion detection with transformer-based alerts correlation

  • Abdelkader Bouguessa,
  • Sid Ahmed Mokhtar Mostefaoui,
  • Mohamed Amine Daoud,
  • Abdelkader Alem,
  • Said Mekroussi,
  • Moustafa Maasakri,
  • Ahmed Hasan

摘要

Intrusion Detection Systems (IDS) play a vital role in cybersecurity by identifying and mitigating malicious activities in network traffic. However, the high volume of alerts often leads to false positives, alert fatigue, and missed threats. Conventional IDS methods detect isolated anomalies primarily, but fail to capture temporal and contextual relationships between alerts. To address these limitations, we introduce an IDS model that utilizes transformer-based encoder attention mechanisms. Inspired by advances in natural language processing, our approach dynamically prioritizes alerts based on context, enhancing the detection of critical threats and uncovering hidden attack patterns. This significantly reduces false positives while improving detection accuracy. By carefully tuning the model components such as the number of encoder layers, attention heads, batch size, and feedforward layer size, our model achieved a classification accuracy of 99.34% with an error rate of just 0.55% on the test data. These results highlight the effectiveness of encoder attention mechanisms in optimizing IDS performance, particularly when combined with dense neural layers, demonstrating the potential of Transformer-based models in developing more adaptive and intelligent IDS.