Machine Learning and Deep Learning Methods for Intrusion Detection Systems: A Survey
Методы машинного и глубокого обучения для систем обнаружения вторжений: обзор
2019-10-17
SCID: 54.1/ywcv5u7d
Discuss with AI
benchmark datasetscybersecuritydeep learningintrusion detection systemsmachine learning
Figures from the paper
Abstract (AI)
Networks play important roles in modern life, and cyber security has become a vital research area. An intrusion detection system (IDS) which is an important cyber security technique, monitors the state of software and hardware running in the network. Despite decades of development, existing IDSs still face challenges in improving the detection accuracy, reducing the false alarm rate and detecting unknown attacks. To solve the above problems, many researchers have focused on developing IDSs that capitalize on machine learning methods. Machine learning methods can automatically discover the essential differences between normal data and abnormal data with high accuracy. In addition, machine learning methods have strong generalizability, so they are also able to detect unknown attacks. Deep learning is a branch of machine learning, whose performance is remarkable and has become a research hotspot. This survey proposes a taxonomy of IDS that takes data objects as the main dimension to classify and summarize machine learning-based and deep learning-based IDS literature. We believe that this type of taxonomy framework is fit for cyber security researchers. The survey first clarifies the concept and taxonomy of IDSs. Then, the machine learning algorithms frequently used in IDSs, metrics, and benchmark datasets are introduced. Next, combined with the representative literature, we take the proposed taxonomic system as a baseline and explain how to solve key IDS issues with machine learning and deep learning techniques. Finally, challenges and future developments are discussed by reviewing recent representative studies.
Key Findings
1
Deep learning, as a branch of machine learning, has shown notable performance and has become a major research focus for intrusion detection.
2
Existing intrusion detection systems still struggle to improve detection accuracy, reduce false alarm rates, and identify unknown attacks.
3
Machine learning can automatically distinguish normal from abnormal network data, while its generalizability supports detection of previously unknown attacks.
4
The survey introduces a taxonomy of machine-learning- and deep-learning-based IDSs that classifies research primarily according to data objects.
5
The survey reviews IDS concepts, algorithms, evaluation metrics, benchmark datasets, representative solutions, and remaining challenges and future directions.
Research Object
Intrusion detection systems (IDS) for computer networks
Research Subject
IDS taxonomy, detection accuracy, false-alarm reduction, and unknown-attack detection capabilities
Publication Details
Publication Date
2019-10-17
Journal
Publisher
ISSN
Cited by
1110
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai7
ImageNet classification with deep convolutional neural networks2017
"Why Should I Trust You?"2016
Empirical Evaluation of Gated Recurrent Neural Networks on Sequence Modeling2014
Bidirectional recurrent neural networks1997
Speech recognition with deep recurrent neural networks2013
A Unified Approach to Interpreting Model Predictions2017
Machine Learning and Deep Learning Methods for Cybersecurity2018