This paper introduces a novel data representation approach for Intrusion Detection Systems (IDS), which integrates temporal and symbolic dimensions by constructing 2D matrices that incorporate the history of packet flows while preserving their temporal order and enhancing contextual richness. These enriched representations are then processed by a custom lightweight Convolutional Neural Network (CNN) designed to capture complex patterns with high efficiency. We have developed a new pooling mechanism that emphasizes recent communication patterns, ensuring the relevance of temporal data, and the creation of a compact yet effective CNN architecture optimized for IDS tasks. The proposed model achieves state-of-the-art performance on the CICIDS2017 dataset, demonstrating superior detection accuracy and robustness across diverse attack classes. By reducing computational complexity and enhancing the contextual representation of network data, our approach offers a significant step forward in the design of effective and scalable IDS solutions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Data Transformation for IDS: Leveraging Symbolic and Temporal Aspects

  • Enzo Zamaï,
  • David Espes,
  • Audrey C. Therrien,
  • Catherine Dezan

摘要

This paper introduces a novel data representation approach for Intrusion Detection Systems (IDS), which integrates temporal and symbolic dimensions by constructing 2D matrices that incorporate the history of packet flows while preserving their temporal order and enhancing contextual richness. These enriched representations are then processed by a custom lightweight Convolutional Neural Network (CNN) designed to capture complex patterns with high efficiency. We have developed a new pooling mechanism that emphasizes recent communication patterns, ensuring the relevance of temporal data, and the creation of a compact yet effective CNN architecture optimized for IDS tasks. The proposed model achieves state-of-the-art performance on the CICIDS2017 dataset, demonstrating superior detection accuracy and robustness across diverse attack classes. By reducing computational complexity and enhancing the contextual representation of network data, our approach offers a significant step forward in the design of effective and scalable IDS solutions.