An ontological-based explainable intrusion detection system
摘要
Cyber-attacks in mobile cloud environments are causes of security concerns nowadays. Intrusion Detection Systems (IDS) play a key role in enhancing the security of cloud systems. However, traditional techniques contribute towards fine IDS; they face several issues such as higher complexity, higher computational resource utilization, lower interpretability, and many more. To mitigate these issues, the given paper introduces an ontology-based explainable IDS equipped with a knowledge base (ontology) and Local Interpretable Model-Agnostic Explanations (LIME) methodology for interpreting the model’s performance. The proposed system involves ontology construction belonging to different categories of attacks in the given network. The designed ontology is treated as a knowledge base for representing concepts and relationships between nodes in the given network. It acts as a powerful tool to detect intrusions in the given network, followed by the LIME explanation mechanism, thus enabling interpretable, instance-specific explanations. Lastly, the performance of the proposed IDS is assessed and validated with existing studies based on metrics such as accuracy (%), precision (%), and recall (%).