The increasing sophistication of cyberattacks has escalated the need for advanced network intrusion detection systems (NIDS). This thesis presents TL-SOINN, an innovative algorithm combining Deep Transfer Learning with a Self-Organizing Incremental Neural Network (SOINN). TL-SOINN leverages the strengths of both approaches, enabling effective learning from diverse datasets and rapid adaptation to new attack types. The model uses a Convolutional Neural Network (CNN) trained on a comprehensive dataset of cyberattacks to extract key features, which are then processed by SOINN. This method allows the system to retain knowledge of known threats while continuously adapting to new ones. Experimental results demonstrate that TL-SOINN outperforms traditional methods in detecting a broad spectrum of cyberattacks, making it a robust solution for evolving network security needs. Additionally, the thesis integrates the Suricata tool to enrich the dataset, enhancing the model’s generalization capabilities across different network environments. The successful application of TL-SOINN across various datasets highlights its potential as an effective and adaptable NIDS solution, capable of improving cybersecurity in increasingly complex and dynamic systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

TL-SOINN: A Transfer Learning-Enhanced Self-organizing Incremental Neural Network for Network Intrusion Detection

  • La Thi Ha,
  • Tran Hoang Hai

摘要

The increasing sophistication of cyberattacks has escalated the need for advanced network intrusion detection systems (NIDS). This thesis presents TL-SOINN, an innovative algorithm combining Deep Transfer Learning with a Self-Organizing Incremental Neural Network (SOINN). TL-SOINN leverages the strengths of both approaches, enabling effective learning from diverse datasets and rapid adaptation to new attack types. The model uses a Convolutional Neural Network (CNN) trained on a comprehensive dataset of cyberattacks to extract key features, which are then processed by SOINN. This method allows the system to retain knowledge of known threats while continuously adapting to new ones. Experimental results demonstrate that TL-SOINN outperforms traditional methods in detecting a broad spectrum of cyberattacks, making it a robust solution for evolving network security needs. Additionally, the thesis integrates the Suricata tool to enrich the dataset, enhancing the model’s generalization capabilities across different network environments. The successful application of TL-SOINN across various datasets highlights its potential as an effective and adaptable NIDS solution, capable of improving cybersecurity in increasingly complex and dynamic systems.