paper-with-me

홈 › Papers

An Evaluation Framework for Network IDS/IPS Datasets: Leveraging MITRE ATT&CK and Industry Relevance Metrics

2025-11-16 · Adrita Rahman Tori, Khondokar Fida Hasan arxiv

The performance of Machine Learning (ML) and Deep Learning (DL)-based Intrusion Detection and Prevention Systems (IDS/IPS) is critically dependent on the relevance and quality of the datasets used for training and evaluation. However, current AI model evaluation practices for developing IDS/IPS focus predominantly on accuracy metrics, often overlooking whether datasets represent industry-specific threats. To address this gap, we introduce a novel multi-dimensional framework that integrates the MITRE ATT&CK knowledge base for threat intelligence and employs five complementary metrics that together provide a comprehensive assessment of dataset suitability. Methodologically, this framework combines threat intelligence, natural language processing, and quantitative analysis to assess the suitability of datasets for specific industry contexts. Applying this framework to nine publicly available IDS/IPS datasets reveals significant gaps in threat coverage, particularly in the healthcare, energy, and financial sectors. In particular, recent datasets (e.g., CIC-IoMT, CIC-UNSW-NB15) align better with sector-specific threats, whereas others, like CICIoV-24, underperform despite their recency. Our findings provide a standardized, interpretable approach for selecting datasets aligned with sector-specific operational requirements, ultimately enhancing the real-world effectiveness of AI-driven IDS/IPS deployments. The efficiency and practicality of the framework are validated through deployment in a real-world case study, underscoring its capacity to inform dataset selection and enhance the effectiveness of AI-driven IDS/IPS in operational environments.

📄 PDF Abstract BibTeX arXiv:2511.12743

Code (0)

등록된 구현이 없습니다.

Tasks

Intrusion Detection

Similar Papers 제목 키워드 기반

MITRE-SAGE: A Multi-Agent Cybersecurity Question-Answering Model

2026-08-03 · Ali Habibzadeh, Farid Feyzi, Reza Ebrahimi Atani arxiv

Effective cybersecurity operations require timely and accurate analysis of large-scale heterogeneous security information; however, analysts increasingly struggle with information overload, alert fatigue, and time-constr…

Question Answering

MiTREE: Multi-input Transformer Ecoregion Encoder for Species Distribution Modelling

2024-12-25 · Theresa Chen, Yao-Yi Chiang

Climate change poses an extreme threat to biodiversity, making it imperative to efficiently model the geographical range of different species. The availability of large-scale remote sensing images and environmental data …

MITRE at SemEval-2018 Task 11: Commonsense Reasoning without Commonsense Knowledge

2018-06-01 · SEMEVAL 2018 6 · Elizabeth Merkhofer, John Henderson, David Bloom, Laura Strickhart 외

This paper describes MITRE{'}s participation in SemEval-2018 Task 11: Machine Comprehension using Commonsense Knowledge. The techniques explored range from simple bag-of-ngrams classifiers to neural architectures with va…

Common Sense ReasoningInformation RetrievalReading Comprehensionregression

Learning the Associations of MITRE ATT&CK Adversarial Techniques

2020-04-16 · Rawan Al-Shaer, Jonathan M. Spring, Eliana Christou

The MITRE ATT&CK Framework provides a rich and actionable repository of adversarial tactics, techniques, and procedures (TTP). However, this information would be highly useful for attack diagnosis (i.e., forensics) and m…

Clustering

International Multicultural Name Matching Competition: Design, Execution, Results, and Lessons Learned

2012-05-01 · LREC 2012 5 · Keith J. Miller, Elizabeth Schroeder Richerson, Sarah McLeod, James Finley 외

This paper describes different aspects of an open competition to evaluate multicultural name matching software, including the contest design, development of the test data, different phases of the competition, behavior of…

Transliteration