<p>Network attacks via zero-days continue to be a challenge in cybersecurity due to their unknown nature, making both signature-based approaches and supervised learning ineffective because of a lack of information needed for classification. On the other hand, anomaly-based models have been proposed to overcome this issue by modeling normal behavior and then detecting anomalies. However, these approaches run into the problem that the penalty of the false positive is rigid for every type of attack and does not vary based on the number of occurrences. In this regard, our solution is Adaptive-<InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(\lambda \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>λ</mi> </math></EquationSource> </InlineEquation> PSO-IF. Isolation Forest is combined with Particle Swarm Optimization (PSO) algorithm so that feature selection and anomaly threshold optimization can be conducted simultaneously for each type of attacks without requiring any labeled attack samples during the optimization process. The novelty of our approach is the rarity-aware regularization of the <InlineEquation ID="IEq2"> <EquationSource Format="TEX">\(\lambda \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>λ</mi> </math></EquationSource> </InlineEquation>-coefficient, an approach that, to our knowledge, has not been previously explored in PSO-driven anomaly detection frameworks and directly addresses the systematic underdetection of rare zero-day families. Experiments on the UNSW-NB15 dataset under a strict Leave-One-Family-Out zero-day evaluation protocol demonstrate that Adaptive-<InlineEquation ID="IEq3"> <EquationSource Format="TEX">\(\lambda \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>λ</mi> </math></EquationSource> </InlineEquation> PSO-IF achieves a mean objective score of 0.176 ± 0.266 across five independent random seeds, outperforming fixed-<InlineEquation ID="IEq4"> <EquationSource Format="TEX">\(\lambda \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>λ</mi> </math></EquationSource> </InlineEquation> PSO-IF by up to 50.9% on rare attack families and standard Isolation Forest by 104.6% in mean objective score, while maintaining competitive performance with LOF at significantly lower inference complexity. The gains are most pronounced in rare attack families, with F1 improvements of 15.0% on Analysis, 20.8% on Reconnaissance, and 50.9% on Backdoor over the fixed-<InlineEquation ID="IEq5"> <EquationSource Format="TEX">\(\lambda \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>λ</mi> </math></EquationSource> </InlineEquation> baseline. The online inference complexity of the deployed system remains <InlineEquation ID="IEq6"> <EquationSource Format="TEX">\(O(t\cdot log \psi ),\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>O</mi> <mo stretchy="false">(</mo> <mi>t</mi> <mo>·</mo> <mi>l</mi> <mi>o</mi> <mi>g</mi> <mi>ψ</mi> <mo stretchy="false">)</mo> <mo>,</mo> </mrow> </math></EquationSource> </InlineEquation> identical to standard Isolation Forest, confirming that the performance gains carry no additional cost at detection time.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An adaptive particle swarm optimization approach to zero-day intrusion detection with rarity-sensitive isolation forest

  • Ahmad Salim

摘要

Network attacks via zero-days continue to be a challenge in cybersecurity due to their unknown nature, making both signature-based approaches and supervised learning ineffective because of a lack of information needed for classification. On the other hand, anomaly-based models have been proposed to overcome this issue by modeling normal behavior and then detecting anomalies. However, these approaches run into the problem that the penalty of the false positive is rigid for every type of attack and does not vary based on the number of occurrences. In this regard, our solution is Adaptive- \(\lambda \) λ PSO-IF. Isolation Forest is combined with Particle Swarm Optimization (PSO) algorithm so that feature selection and anomaly threshold optimization can be conducted simultaneously for each type of attacks without requiring any labeled attack samples during the optimization process. The novelty of our approach is the rarity-aware regularization of the \(\lambda \) λ -coefficient, an approach that, to our knowledge, has not been previously explored in PSO-driven anomaly detection frameworks and directly addresses the systematic underdetection of rare zero-day families. Experiments on the UNSW-NB15 dataset under a strict Leave-One-Family-Out zero-day evaluation protocol demonstrate that Adaptive- \(\lambda \) λ PSO-IF achieves a mean objective score of 0.176 ± 0.266 across five independent random seeds, outperforming fixed- \(\lambda \) λ PSO-IF by up to 50.9% on rare attack families and standard Isolation Forest by 104.6% in mean objective score, while maintaining competitive performance with LOF at significantly lower inference complexity. The gains are most pronounced in rare attack families, with F1 improvements of 15.0% on Analysis, 20.8% on Reconnaissance, and 50.9% on Backdoor over the fixed- \(\lambda \) λ baseline. The online inference complexity of the deployed system remains \(O(t\cdot log \psi ),\) O ( t · l o g ψ ) , identical to standard Isolation Forest, confirming that the performance gains carry no additional cost at detection time.