Network intrusion detection system: A systematic study of machine learning and deep learning approaches
Система обнаружения вторжений в сети: систематическое исследование подходов на основе машинного и глубокого обучения
2020-10-16
SCID: 54.1/xjedhctq
Discuss with AI
deep learningfalse alarm ratemachine learningnetwork intrusion detection systemsnetwork traffic analysis
Figures from the paper
Abstract (AI)
Abstract The rapid advances in the internet and communication fields have resulted in a huge increase in the network size and the corresponding data. As a result, many novel attacks are being generated and have posed challenges for network security to accurately detect intrusions. Furthermore, the presence of the intruders with the aim to launch various attacks within the network cannot be ignored. An intrusion detection system (IDS) is one such tool that prevents the network from possible intrusions by inspecting the network traffic, to ensure its confidentiality, integrity, and availability. Despite enormous efforts by the researchers, IDS still faces challenges in improving detection accuracy while reducing false alarm rates and in detecting novel intrusions. Recently, machine learning (ML) and deep learning (DL)‐based IDS systems are being deployed as potential solutions to detect intrusions across the network in an efficient manner. This article first clarifies the concept of IDS and then provides the taxonomy based on the notable ML and DL techniques adopted in designing network‐based IDS (NIDS) systems. A comprehensive review of the recent NIDS‐based articles is provided by discussing the strengths and limitations of the proposed solutions. Then, recent trends and advancements of ML and DL‐based NIDS are provided in terms of the proposed methodology, evaluation metrics, and dataset selection. Using the shortcomings of the proposed methods, we highlighted various research challenges and provided the future scope for the research in improving ML and DL‐based NIDS.
Key Findings
1
Dataset selection, methodological design, and evaluation practices are emphasized as important factors shaping reported NIDS performance.
2
It systematically reviews recent NIDS studies, comparing their methodologies, evaluation metrics, datasets, strengths, and limitations.
3
Machine learning and deep learning are identified as promising approaches for improving intrusion detection efficiency, but accuracy, false alarms, and novel-attack detection remain unresolved challenges.
4
The paper presents a taxonomy of machine learning and deep learning techniques used to design network-based intrusion detection systems.
5
The review highlights research gaps and proposes future directions for developing more accurate and robust ML- and DL-based NIDS.
Research Object
Network-based intrusion detection system (NIDS)
Research Subject
the effectiveness and challenges of machine-learning- and deep-learning-based intrusion detection, including detection accuracy, false alarm reduction, and novel-intrusion detection
Publication Details
Publication Date
2020-10-16
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest