Self-Adaptive Lightweight Attention Module-Based BiLSTM Model for Effective Intrusion Detection
摘要
The increasing prevalence of computer network attacks globally has created a need for enhanced intrusion detection and prevention solutions. Traditional intrusion detection systems often struggle to differentiate genuine network traffic from malicious DDoS attacks especially, in case of low-rate or stealthy incursions. Signature-based and rule-based systems face challenges in adapting the emerging attack patterns, resulting in a high false-positive rate that can overwhelm security teams with irrelevant alerts. To address these limitations, this research introduces the self-adaptive lightweight attention module-based bidirectional long short-term memory (SLWAM-BiLSTM), which involves spatial and channel attention mechanisms, to enhance its ability to discern malicious activity from normal network behavior. The self-adaptive nature of the attention modules ensures that the model can dynamically adjust its focus, making the model well-suited for real-time intrusion detection. The spatial and channel attention mechanisms are employed to optimize the model. Additionally, the drift evaluation mechanism implemented in this research is a dynamic assessment mechanism that adaptively monitors the network traffic behavior and manages emerging attack patterns. The experimental outcomes reveal that the SLWAM-BiLSTM model has a higher sensitivity of 93.91%, specificity of 97.31%, and overall accuracy of 96.91%, at TP 80% while using the CIC-DDoS2019 dataset, outperforming conventional approaches in DDoS attack.