Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

A Dynamic Intrusion Detection System Capable of Detecting Unknown Attacks

Author 1: Na Xing Author 2: Shuai Zhao Author 3: Yuehai Wang Author 4: Keqing Ning Author 5: Xiufeng Liu
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 14, No. 7 · Published 2023 · Cited by 8

DOI: https://doi.org/10.14569/IJACSA.2023.0140743

Abstract

In recent years, deep learning-based network intrusion detection systems (IDS) have shown impressive results in detecting attacks. However, most existing IDS can only recognize known attacks that were included in their training data. When faced with unknown attacks, these systems are often unable to take appropriate actions and incorrectly classify them into known categories, leading to reduced detection performance. Furthermore, as the number and types of network attacks continue to increase, it becomes challenging for these IDS to update their model parameters promptly and adapt to new attack scenarios. To address these issues, this paper introduces a dynamic intrusion detection system, Dynamic Unknown Attack Intrusion Detection System (DUA-IDS). This system aims to learn and detect unknown attacks effectively. DUA-IDS comprises three components: Feature Extractor: This component employs CNN and Transformer models to extract data features from various perspectives. Threshold-Based Classifier: The second part utilizes the nearest mean rule of samples to classify known and unknown attacks, enabling the distinction between them. Dynamic Learning Module: The third part incorporates data playback and knowledge distillation techniques to retain existing category knowledge while continuously learning new attack categories. To assess the effectiveness of DUA-IDS, this paper conducted experiments using the UNSW-NB15 public dataset. The experimental results show that DUA-IDS improves the classification accuracy of flow network data with unknown traffic attacks. Can accurately distinguish unknown traffic and correctly classify known traffic. When dynamically learning unknown traffic, the classification accuracy of previously learned known traffic is less affected. This indicates the advantages of DUA-IDS in detecting unknown attacks and learning new attack categories.

Keywords

How to Cite this Article

Xing, N., Zhao, S., Wang, Y., Ning, K., & Liu, X. (2023). A Dynamic Intrusion Detection System Capable of Detecting Unknown Attacks. International Journal of Advanced Computer Science and Applications, 14(7). https://doi.org/10.14569/IJACSA.2023.0140743

Xing, Na, et al.. "A Dynamic Intrusion Detection System Capable of Detecting Unknown Attacks." International Journal of Advanced Computer Science and Applications, vol. 14, no. 7, 2023, https://doi.org/10.14569/IJACSA.2023.0140743.

@article{Xing2023,
  title     = {A Dynamic Intrusion Detection System Capable of Detecting Unknown Attacks},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {14},
  number    = {7},
  year      = {2023},
  publisher = {The Science and Information Organization},
  author    = {Na Xing and Shuai Zhao and Yuehai Wang and Keqing Ning and Xiufeng Liu},
  doi       = {10.14569/IJACSA.2023.0140743},
  url       = {https://doi.org/10.14569/IJACSA.2023.0140743}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.