Machine Learning for Intrusion Detection Systems: A Systematic Literature Review
摘要
As the world continues to digitise, the threat of cyberattacks increases. Cyber-attacks are becoming more common and complex, making them more difficult to detect and prevent. Cybersecurity breaches have increased in several domains, including automation, industrial processes, smart homes, healthcare, and energy. Cyberattacks can have several negative consequences; financial loss, disruption of operations and loss of important data are the most noticeable and immediate effects of cyberattacks on a person or organisation. One of the solid cyber security policies is intrusion detection systems. Implementing machine learning (ML) based intrusion detection systems could improve the accuracy and effectiveness of intrusion detection systems. This paper provides a systematic review of the machine learning approaches for intrusion detection systems (IDS). We looked into the applications of machine learning, and the challenges associated with implementing machine learning for intrusion detection systems. The findings show that Support Vector Machines (SVM), K-Nearest Neighbour (KNN), Decision Tree (DT), Convolutional Neural Networks (CNN), Random Forests, Naïve Bayes, and ANN algorithms are the most commonly used machine learning algorithms for IDS. Several challenges associated with implementing machine learning in intrusion detection systems such as data acquisition and processing, training and retraining the machine learning models, thoroughly testing the models, selecting the best datasets and features, and data poisoning were also identified. This indicates that while there are current applications for machine learning in intrusion detection systems, there are still some challenges that need to be addressed to increase the adoption of machine learning-based intrusion detection systems.