<p>Advanced cyber threats are increasingly targeting Industrial Cyber-Physical Systems (ICPS), posing critical challenges for cybersecurity in smart industries. Conventional intrusion detection systems (IDS) often struggle to detect complex attacks due to limited threat visibility, poor adaptability, and lack of interpretability, restricting timely and informed decision-making. To overcome these limitations, we propose SmartHive-IDS, an advanced intrusion detection framework for SDN-HoneyNet-enabled ICPS. A key innovation of SmartHive-IDS lies in its feature selection strategy, which integrates SHAP (SHapley Additive exPlanations) with a suite of statistical and model-based techniques. These include Chi-Squared analysis, Mutual Information, Information Gain, Correlation Analysis, and the Boruta algorithm, enabling the framework to accurately identify and prioritize the most relevant features for intrusion detection. The combination enhances the feature’s relevance, transparency, and interpretability in the detection process. For intrusion detection, a bidirectional long short-term memory (Bi-LSTM) model captures temporal dependencies within network traffic. Its settings are carefully adjusted using a mix of different optimization methods, such as Bayesian Optimization (BO), Ant Colony Optimization (ACO), Genetic Algorithm (GA), and Particle Swarm Optimization (PSO). Additionally, an ensemble voting mechanism aggregates the softmax probabilities of multiple optimized models to improve generalization and stability. The SmartHive-IDS method outperforms traditional IDS methods on benchmark datasets NSL-KDD, CICIDS-2018, and TON_IoT. The proposed framework achieved an improved detection accuracy of 98.96% and a reduced false positive rate of 0.012%, confirming its superior detection capability and robustness. Empirical results showed that SmartHive-IDS offers a scalable, interpreted, and high-performance cybersecurity solution for securing smart industrial environments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SmartHive-IDS: an advanced intrusion detection framework for SDN-HoneyNet enabled ICPS using hybrid explainable ensemble feature selection with optimized Bi-LSTM

  • S. Krishnaveni,
  • Sherali Zeadally,
  • S. Sivamohan,
  • S. S. Sridhar

摘要

Advanced cyber threats are increasingly targeting Industrial Cyber-Physical Systems (ICPS), posing critical challenges for cybersecurity in smart industries. Conventional intrusion detection systems (IDS) often struggle to detect complex attacks due to limited threat visibility, poor adaptability, and lack of interpretability, restricting timely and informed decision-making. To overcome these limitations, we propose SmartHive-IDS, an advanced intrusion detection framework for SDN-HoneyNet-enabled ICPS. A key innovation of SmartHive-IDS lies in its feature selection strategy, which integrates SHAP (SHapley Additive exPlanations) with a suite of statistical and model-based techniques. These include Chi-Squared analysis, Mutual Information, Information Gain, Correlation Analysis, and the Boruta algorithm, enabling the framework to accurately identify and prioritize the most relevant features for intrusion detection. The combination enhances the feature’s relevance, transparency, and interpretability in the detection process. For intrusion detection, a bidirectional long short-term memory (Bi-LSTM) model captures temporal dependencies within network traffic. Its settings are carefully adjusted using a mix of different optimization methods, such as Bayesian Optimization (BO), Ant Colony Optimization (ACO), Genetic Algorithm (GA), and Particle Swarm Optimization (PSO). Additionally, an ensemble voting mechanism aggregates the softmax probabilities of multiple optimized models to improve generalization and stability. The SmartHive-IDS method outperforms traditional IDS methods on benchmark datasets NSL-KDD, CICIDS-2018, and TON_IoT. The proposed framework achieved an improved detection accuracy of 98.96% and a reduced false positive rate of 0.012%, confirming its superior detection capability and robustness. Empirical results showed that SmartHive-IDS offers a scalable, interpreted, and high-performance cybersecurity solution for securing smart industrial environments.