<p>Cyber-attacks in mobile cloud environments are causes of security concerns nowadays. Intrusion Detection Systems (IDS) play a key role in enhancing the security of cloud systems. However, traditional techniques contribute towards fine IDS; they face several issues such as higher complexity, higher computational resource utilization, lower interpretability, and many more. To mitigate these issues, the given paper introduces an ontology-based explainable IDS equipped with a knowledge base (ontology) and Local Interpretable Model-Agnostic Explanations (LIME) methodology for interpreting the model’s performance. The proposed system involves ontology construction belonging to different categories of attacks in the given network. The designed ontology is treated as a knowledge base for representing concepts and relationships between nodes in the given network. It acts as a powerful tool to detect intrusions in the given network, followed by the LIME explanation mechanism, thus enabling interpretable, instance-specific explanations. Lastly, the performance of the proposed IDS is assessed and validated with existing studies based on metrics such as accuracy (%), precision (%), and recall (%).</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An ontological-based explainable intrusion detection system

  • Sandeep Sharma,
  • Nitin Rakesh,
  • Megha Jagga,
  • Harminder Singh,
  • Madhu Kirola,
  • Ram Subbiah,
  • Neeraj Varshney,
  • Layth Hussein,
  • Nikolai Ivanovich Vatin

摘要

Cyber-attacks in mobile cloud environments are causes of security concerns nowadays. Intrusion Detection Systems (IDS) play a key role in enhancing the security of cloud systems. However, traditional techniques contribute towards fine IDS; they face several issues such as higher complexity, higher computational resource utilization, lower interpretability, and many more. To mitigate these issues, the given paper introduces an ontology-based explainable IDS equipped with a knowledge base (ontology) and Local Interpretable Model-Agnostic Explanations (LIME) methodology for interpreting the model’s performance. The proposed system involves ontology construction belonging to different categories of attacks in the given network. The designed ontology is treated as a knowledge base for representing concepts and relationships between nodes in the given network. It acts as a powerful tool to detect intrusions in the given network, followed by the LIME explanation mechanism, thus enabling interpretable, instance-specific explanations. Lastly, the performance of the proposed IDS is assessed and validated with existing studies based on metrics such as accuracy (%), precision (%), and recall (%).