Network intrusion detection system: A systematic study of machine learning and deep learning approaches

Система обнаружения вторжений в сети: систематическое исследование подходов на основе машинного и глубокого обучения
Farhan Ahmad, Adnan Shahid Khan, Zeeshan Ahmad, Johari Abdullah, Cheah Wai Shiang
2020-10-16

deep learningfalse alarm ratemachine learningnetwork intrusion detection systemsnetwork traffic analysis
Abstract The rapid advances in the internet and communication fields have resulted in a huge increase in the network size and the corresponding data. As a result, many novel attacks are being generated and have posed challenges for network security to accurately detect intrusions. Furthermore, the presence of the intruders with the aim to launch various attacks within the network cannot be ignored. An intrusion detection system (IDS) is one such tool that prevents the network from possible intrusions by inspecting the network traffic, to ensure its confidentiality, integrity, and availability. Despite enormous efforts by the researchers, IDS still faces challenges in improving detection accuracy while reducing false alarm rates and in detecting novel intrusions. Recently, machine learning (ML) and deep learning (DL)‐based IDS systems are being deployed as potential solutions to detect intrusions across the network in an efficient manner. This article first clarifies the concept of IDS and then provides the taxonomy based on the notable ML and DL techniques adopted in designing network‐based IDS (NIDS) systems. A comprehensive review of the recent NIDS‐based articles is provided by discussing the strengths and limitations of the proposed solutions. Then, recent trends and advancements of ML and DL‐based NIDS are provided in terms of the proposed methodology, evaluation metrics, and dataset selection. Using the shortcomings of the proposed methods, we highlighted various research challenges and provided the future scope for the research in improving ML and DL‐based NIDS.
1
Dataset selection, methodological design, and evaluation practices are emphasized as important factors shaping reported NIDS performance.
2
It systematically reviews recent NIDS studies, comparing their methodologies, evaluation metrics, datasets, strengths, and limitations.
3
Machine learning and deep learning are identified as promising approaches for improving intrusion detection efficiency, but accuracy, false alarms, and novel-attack detection remain unresolved challenges.
4
The paper presents a taxonomy of machine learning and deep learning techniques used to design network-based intrusion detection systems.
5
The review highlights research gaps and proposes future directions for developing more accurate and robust ML- and DL-based NIDS.

Network-based intrusion detection system (NIDS)

the effectiveness and challenges of machine-learning- and deep-learning-based intrusion detection, including detection accuracy, false alarm reduction, and novel-intrusion detection

Publication Details
Publication Date
2020-10-16
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Farhan Ahmad
Adnan Shahid Khan
Zeeshan Ahmad
Johari Abdullah
Cheah Wai Shiang
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%