<p>The rise of Internet technology has been instrumental in the advancement of communication networks. Consequently, it has also resulted in networks being increasingly conducive to cyberattacks. Intrusion detection systems (IDSs), facilitating proactive detection of malicious behavior, are critical to network security. Conventional approaches, however, suffer from significant shortcomings: Signature-based IDS is constrained by the ability to recognize novel attacks since it relies on pre-established patterns, whereas anomaly-based IDS generates false alarms owing to the changes in normal traffic. This paper presents DLC-IDS, the new hybrid intrusion detection framework that combines the strengths of both approaches without their limitations. Envisaged on the principles of democratic leadership, DLC-IDS comprises a central multi-class classifier (leader) with the support of multiple subordinate classifiers, each adept at detecting a particular attack. Unlike traditional approaches, DLC-IDS dynamically leverages the knowledge of subordinate classifiers to refine detection decisions, thereby improving accuracy and reducing false negatives. Integrating advanced techniques like long short-term memory (LSTM) networks with self-attention and conditional tabular generative adversarial network (CTGAN)-based data augmentation, DLC-IDS handles imbalanced datasets and detects novel patterns of attacks effectively. Tested on the NSL-KDD, ORNL Formatted SCADA Gas Pipeline, and ARFF Formatted New Gas Pipeline datasets, DLC-IDS outperforms current IDS models in overall accuracy and achieves a very low false negative percentage, demonstrating its ability to solve the dynamic issues of cybersecurity.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DLC-IDS: a novel democratic leadership classification model for intrusion detection systems

  • Sourajit Chakravarty,
  • Soham Satpati,
  • Saptarshi Das,
  • Chirantana Mallick,
  • Kausik Basak,
  • Arun Kumar Majumdar

摘要

The rise of Internet technology has been instrumental in the advancement of communication networks. Consequently, it has also resulted in networks being increasingly conducive to cyberattacks. Intrusion detection systems (IDSs), facilitating proactive detection of malicious behavior, are critical to network security. Conventional approaches, however, suffer from significant shortcomings: Signature-based IDS is constrained by the ability to recognize novel attacks since it relies on pre-established patterns, whereas anomaly-based IDS generates false alarms owing to the changes in normal traffic. This paper presents DLC-IDS, the new hybrid intrusion detection framework that combines the strengths of both approaches without their limitations. Envisaged on the principles of democratic leadership, DLC-IDS comprises a central multi-class classifier (leader) with the support of multiple subordinate classifiers, each adept at detecting a particular attack. Unlike traditional approaches, DLC-IDS dynamically leverages the knowledge of subordinate classifiers to refine detection decisions, thereby improving accuracy and reducing false negatives. Integrating advanced techniques like long short-term memory (LSTM) networks with self-attention and conditional tabular generative adversarial network (CTGAN)-based data augmentation, DLC-IDS handles imbalanced datasets and detects novel patterns of attacks effectively. Tested on the NSL-KDD, ORNL Formatted SCADA Gas Pipeline, and ARFF Formatted New Gas Pipeline datasets, DLC-IDS outperforms current IDS models in overall accuracy and achieves a very low false negative percentage, demonstrating its ability to solve the dynamic issues of cybersecurity.