NIDS-CBAD: detecting adversarial attacks in network intrusion detection systems using domain constraints
摘要
Deep learning has witnessed continuous improvement over the years, which has led to its application with notable results in several areas, including the development of Network intrusion detection systems (NIDS). However, such learning models are susceptible to adversarial attacks, whereby an imperceptible change in an input data sample can cause misclassification. Adversarial attacks in security-critical applications like NIDS can easily compromise network security and, therefore, require effective countermeasure techniques. In this paper, we propose NIDS-CBAD, a constraint based adversarial detection technique for NIDS. We show that it is possible to detect adversarial examples using the inherent constraints of features derived from a network flow. Unlike prevalent detection techniques, NIDS-CBAD relaxes the requirement of generating adversarial examples for training and also does not need an auxiliary classifier. This reduces the computational requirement as we use constraint violations to detect adversarial attacks. NIDS-CBAD even detects practical adversarial examples specifically designed to obey network constraints. The detection method is simple yet effective in its approach and poses difficulty even for a strong adversary in crafting successful attacks. We evaluate the performance of NIDS-CBAD on three prevalent intrusion datasets: NSL-KDD, UNSW-NB15 and CICIDS2017 against five state-of-the-art adversarial attacks. Experimentally, the proposed method yields an adversarial detection rate of upto 100