Expectations Versus Reality: Evaluating Intrusion Detection Systems in Practice
Our paper provides empirical comparisons between recent IDSs to provide an objective comparison between them to help users choose the most appropriate solution based on their requirements. Our results show that no one solution is the best, but is dependent on external variables such as the types of attacks, complexity, and network environment in the dataset. For example, BoT_IoT and Stratosphere IoT datasets both capture IoT-related attacks, but the deep neural network performed the best when tested using the BoT_IoT dataset while HELAD performed the best when tested using the Stratosphere IoT dataset. So although we found that a deep neural network solution had the highest average F1 scores on tested datasets, it is not always the best-performing one. We further discuss difficulties in using IDS from literature and project repositories, which complicated drawing definitive conclusions regarding IDS selection.
Code (0)
등록된 구현이 없습니다.
Tasks
Intrusion DetectionSimilar Papers 제목 키워드 기반
Intrusion detection systems using classical machine learning techniques versus integrated unsupervised feature learning and deep neural network
Security analysts and administrators face a lot of challenges to detect and prevent network intrusions in their organizations, and to prevent network breaches, detecting the breach on time is crucial. Challenges arise wh…
BIG-bench Machine LearningFeature EngineeringIntrusion DetectionEnd-to-End Adversarial Learning for Intrusion Detection in Computer Networks
This paper presents a simple yet efficient method for an anomaly-based Intrusion Detection System (IDS). In reality, IDSs can be defined as a one-class classification system, where the normal traffic is the target class.…
DiversityIntrusion DetectionOne-Class ClassificationMachine Learning-Based Intrusion Detection: Feature Selection versus Feature Extraction
Internet of things (IoT) has been playing an important role in many sectors, such as smart cities, smart agriculture, smart healthcare, and smart manufacturing. However, IoT devices are highly vulnerable to cyber-attacks…
feature selectionIntrusion DetectionNetwork Intrusion DetectionEvaluating the Robustness of Time Series Anomaly and Intrusion Detection Methods against Adversarial Attacks
Time series anomaly and intrusion detection are extensively studied in statistics, economics, and computer science. Over the years, numerous methods have been proposed for time series anomaly and intrusion detection usin…
Intrusion DetectionTime SeriesTime Series AnalysisWhat Does Normal Even Mean? Evaluating Benign Traffic in Intrusion Detection Datasets
Supervised machine learning techniques rely on labeled data to achieve high task performance, but this requires the labels to capture some meaningful differences in the underlying data structure. For training network int…
Network Intrusion Detection