Individual Packet Features are a Risk to Model Generalisation in ML-Based Intrusion Detection
Machine learning is increasingly used for intrusion detection in IoT networks. This paper explores the effectiveness of using individual packet features (IPF), which are attributes extracted from a single network packet, such as timing, size, and source-destination information. Through literature review and experiments, we identify the limitations of IPF, showing they can produce misleadingly high detection rates. Our findings emphasize the need for approaches that consider packet interactions for robust intrusion detection. Additionally, we demonstrate that models based on IPF often fail to generalize across datasets, compromising their reliability in diverse IoT environments.
Code (1)
Tasks
Intrusion DetectionSimilar Papers 제목 키워드 기반
Flow Exporter Impact on Intelligent Intrusion Detection Systems
High-quality datasets are critical for training machine learning models, as inconsistencies in feature generation can hinder the accuracy and reliability of threat detection. For this reason, ensuring the quality of the …
Intrusion DetectionNetwork Intrusion DetectionA survey on deep packet inspection for intrusion detection systems
Deep packet inspection is widely recognized as a powerful way which is used for intrusion detection systems for inspecting, deterring and deflecting malicious at- tacks over the network. Fundamentally, almost intru- sion…
Intrusion DetectionSurveyTANTRA: Timing-Based Adversarial Network Traffic Reshaping Attack
Network intrusion attacks are a known threat. To detect such attacks, network intrusion detection systems (NIDSs) have been developed and deployed. These systems apply machine learning models to high-dimensional vectors …
Intrusion DetectionNetwork Intrusion DetectionPacket2Vec: Utilizing Word2Vec for Feature Extraction in Packet Data
One of deep learning's attractive benefits is the ability to automatically extract relevant features for a target problem from largely raw data, instead of utilizing human engineered and error prone handcrafted features.…
General Classificationimage-classificationImage ClassificationIntrusion DetectionAutomated and Explainable Denial of Service Analysis for AI-Driven Intrusion Detection Systems
With the increasing frequency and sophistication of Distributed Denial of Service (DDoS) attacks, it has become critical to develop more efficient and interpretable detection methods. Traditional detection systems often …
Intrusion Detection