Machine Learning and Deep Learning Methods for Intrusion Detection Systems: A Survey

Методы машинного и глубокого обучения для систем обнаружения вторжений: обзор
Bo Lang, Hongyu Liu
2019-10-17

benchmark datasetscybersecuritydeep learningintrusion detection systemsmachine learning
Networks play important roles in modern life, and cyber security has become a vital research area. An intrusion detection system (IDS) which is an important cyber security technique, monitors the state of software and hardware running in the network. Despite decades of development, existing IDSs still face challenges in improving the detection accuracy, reducing the false alarm rate and detecting unknown attacks. To solve the above problems, many researchers have focused on developing IDSs that capitalize on machine learning methods. Machine learning methods can automatically discover the essential differences between normal data and abnormal data with high accuracy. In addition, machine learning methods have strong generalizability, so they are also able to detect unknown attacks. Deep learning is a branch of machine learning, whose performance is remarkable and has become a research hotspot. This survey proposes a taxonomy of IDS that takes data objects as the main dimension to classify and summarize machine learning-based and deep learning-based IDS literature. We believe that this type of taxonomy framework is fit for cyber security researchers. The survey first clarifies the concept and taxonomy of IDSs. Then, the machine learning algorithms frequently used in IDSs, metrics, and benchmark datasets are introduced. Next, combined with the representative literature, we take the proposed taxonomic system as a baseline and explain how to solve key IDS issues with machine learning and deep learning techniques. Finally, challenges and future developments are discussed by reviewing recent representative studies.
1
Deep learning, as a branch of machine learning, has shown notable performance and has become a major research focus for intrusion detection.
2
Existing intrusion detection systems still struggle to improve detection accuracy, reduce false alarm rates, and identify unknown attacks.
3
Machine learning can automatically distinguish normal from abnormal network data, while its generalizability supports detection of previously unknown attacks.
4
The survey introduces a taxonomy of machine-learning- and deep-learning-based IDSs that classifies research primarily according to data objects.
5
The survey reviews IDS concepts, algorithms, evaluation metrics, benchmark datasets, representative solutions, and remaining challenges and future directions.

Intrusion detection systems (IDS) for computer networks

IDS taxonomy, detection accuracy, false-alarm reduction, and unknown-attack detection capabilities

Publication Details
Publication Date
2019-10-17
Journal
Publisher
ISSN
Cited by
1110
Access Type
Author Information
Authors
Bo Lang
Hongyu Liu
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat →
Make a presentation
100%