<p>A Network Intrusion Detection System (NIDS) analyzes network traffic to identify potential threats and unauthorized access, providing alerts for timely action. However, existing works didn’t concentrate on detecting unknown attacks based on packet structure, behavior, and network traffic. Hence, this paper proposes an enhanced NIDS with network harmony analysis and alert prioritization using TL-MD-ADP-BiLSTM, KM-E-GB-SSC, and CMF-Fuzzy. First, the nodes are initialized. Next, the cluster head is selected using GB-SSOA, followed by clustering using KM-E-GB-SSC. Once clustering is complete, the data is sensed for transmission. The sensed data is then secured using S<sup>2</sup>LCC. Next, the Intrusion Detection System (IDS) model is trained on the dataset. This process involves pre-processing and feature extraction, followed by feature selection via GB-SSOA. Classification is then performed using TL-MD-ADP-BiLSTM. This step classifies the data as normal, attack types, or unknown attacks. Normal data is sent to the destination. Attack types undergo alert prioritization using CMF-Fuzzy. Afterward, the prioritized attacks are blocked accordingly, and an alert is sent to the user. Then, unknown attacks undergo feature extraction, and the network harmony analysis is performed using KM-E-GB-SSC. The attack is then blocked, and an alert is sent to the user. Thus, the model successfully classifies the attacks and achieves 98.23% accuracy on the CSE-CIC-IDS2018 and 99.12% accuracy on the CIC-DDoS2019 Dataset.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

NIDS-APNHA: a transfer learning based network intrusion detection system with alert prioritization and network harmony analysis

  • R. C. Jeyavim Sherin,
  • K. Parkavi

摘要

A Network Intrusion Detection System (NIDS) analyzes network traffic to identify potential threats and unauthorized access, providing alerts for timely action. However, existing works didn’t concentrate on detecting unknown attacks based on packet structure, behavior, and network traffic. Hence, this paper proposes an enhanced NIDS with network harmony analysis and alert prioritization using TL-MD-ADP-BiLSTM, KM-E-GB-SSC, and CMF-Fuzzy. First, the nodes are initialized. Next, the cluster head is selected using GB-SSOA, followed by clustering using KM-E-GB-SSC. Once clustering is complete, the data is sensed for transmission. The sensed data is then secured using S2LCC. Next, the Intrusion Detection System (IDS) model is trained on the dataset. This process involves pre-processing and feature extraction, followed by feature selection via GB-SSOA. Classification is then performed using TL-MD-ADP-BiLSTM. This step classifies the data as normal, attack types, or unknown attacks. Normal data is sent to the destination. Attack types undergo alert prioritization using CMF-Fuzzy. Afterward, the prioritized attacks are blocked accordingly, and an alert is sent to the user. Then, unknown attacks undergo feature extraction, and the network harmony analysis is performed using KM-E-GB-SSC. The attack is then blocked, and an alert is sent to the user. Thus, the model successfully classifies the attacks and achieves 98.23% accuracy on the CSE-CIC-IDS2018 and 99.12% accuracy on the CIC-DDoS2019 Dataset.