Intrusion Detection Systems (IDS) are essential for monitoring network traffic and detecting anomalous behavior within network traffic, especially as new attack vectors evolve and evade traditional detection methods. Thus, online learning offers a practical solution by allowing real-time continuous model updates with incoming data to adapt to zero-day attacks. It’s still quite difficult to train efficient IDS models that strike a balance between using historical data and adjusting to new threats. To address this, we introduce an ensemble learning model with active learning, using weighted voting to predict the result with the most accurate model and entropy-based sampling to select the most uncertain and certain samples. It iteratively improves model performance by retraining on selected high and low-uncertainty samples. Our approach aims to reduce the cost of labeling by reducing the need for minimally labeled data while improving detection accuracy. It presents a methodology that optimizes model adaptability and detection quality with minimal labeled data, demonstrated through experimental results on the NSL-KDD dataset. In a complex organizational network, a feature-split ensemble model enhances security by dividing tasks among specialized models, ensuring complete protection and adaptability.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing Network Intrusion Detection Through Adaptive Maximum Disagreement

  • Punit Kumar,
  • Deepak Negi

摘要

Intrusion Detection Systems (IDS) are essential for monitoring network traffic and detecting anomalous behavior within network traffic, especially as new attack vectors evolve and evade traditional detection methods. Thus, online learning offers a practical solution by allowing real-time continuous model updates with incoming data to adapt to zero-day attacks. It’s still quite difficult to train efficient IDS models that strike a balance between using historical data and adjusting to new threats. To address this, we introduce an ensemble learning model with active learning, using weighted voting to predict the result with the most accurate model and entropy-based sampling to select the most uncertain and certain samples. It iteratively improves model performance by retraining on selected high and low-uncertainty samples. Our approach aims to reduce the cost of labeling by reducing the need for minimally labeled data while improving detection accuracy. It presents a methodology that optimizes model adaptability and detection quality with minimal labeled data, demonstrated through experimental results on the NSL-KDD dataset. In a complex organizational network, a feature-split ensemble model enhances security by dividing tasks among specialized models, ensuring complete protection and adaptability.