Intrusion Detection Systems (IDS) are essential for protecting network infrastructure from malicious activities. However, the effectiveness of AI-driven IDS is often compromised by the scarcity of labeled data and high false-alarm rates. Semi-Supervised Learning (SSL) offers a potential solution to the data labeling problem, but existing SSL approaches have shown limited success in the IDS domain. In this paper, we propose a novel Artificial Immune System-based IDS (AIS-IDS) architecture. We instantiate this architecture as SMARTI, an SSL-based AIS-IDS designed to operate effectively without labeled threat data and to minimize false positives by leveraging the self/non-self model of immunology. Our experimental results demonstrate that SMARTI achieves up to 96.7% accuracy, operating at parity with or surpassing state-of-the-art models, while maintaining a near-zero false positive rate and near-perfect specificity. These findings indicate that SMARTI effectively addresses the challenges of high false-alarm rates and limited data labels in IDS, offering a promising direction for enhancing network security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Leveraging Artificial Immune Systems for Semi-supervised Intrusion Detection

  • William Anderson,
  • Jesse Ables,
  • Sudip Mittal,
  • Shahram Rahimi,
  • Ioana Banicescu,
  • Thomas Arnold,
  • Joshua Church,
  • Joseph Jabour

摘要

Intrusion Detection Systems (IDS) are essential for protecting network infrastructure from malicious activities. However, the effectiveness of AI-driven IDS is often compromised by the scarcity of labeled data and high false-alarm rates. Semi-Supervised Learning (SSL) offers a potential solution to the data labeling problem, but existing SSL approaches have shown limited success in the IDS domain. In this paper, we propose a novel Artificial Immune System-based IDS (AIS-IDS) architecture. We instantiate this architecture as SMARTI, an SSL-based AIS-IDS designed to operate effectively without labeled threat data and to minimize false positives by leveraging the self/non-self model of immunology. Our experimental results demonstrate that SMARTI achieves up to 96.7% accuracy, operating at parity with or surpassing state-of-the-art models, while maintaining a near-zero false positive rate and near-perfect specificity. These findings indicate that SMARTI effectively addresses the challenges of high false-alarm rates and limited data labels in IDS, offering a promising direction for enhancing network security.