In our gradual expansion of digital environments, where the growth of cyberattacks has become more frequent, the need for a real-time intrusion detection system (IDS) has become crucial. Traditional IDS models often fail to detect vulnerabilities in dynamically evolving networks, accentuating the need for adaptive solutions. Addressing this challenge, this paper proposes a novel hybrid incremental learning framework for anomaly-based intrusion detection called HIL-IDS. Initially, real-time packet sniffing and feature extraction using Scapy are executed to process raw network traffic. HIL-IDS integrates the Hoeffding tree for incremental supervised learning and an ensemble of isolation forest and KMeans for unsupervised anomaly detection. Confidence scores from the combination of these supervised and unsupervised models are evaluated to enhance the interpretability of the proposed framework. Drift detection is performed to preserve the robustness against the shifting data distributions of the real-time traffic and to adapt new emergent patterns. The proposed model is trained on the CSE-CIC-IDS2018 intrusion detection dataset, a comprehensive benchmark that includes modern attack types. Experimental results show that the proposed hybrid incremental learning approach-based IDS effectively acquires and adjusts to emerging attack patterns. It achieves the highest accuracy of 98.88%, maintaining real-time efficiency and an effective solution towards strengthening the dynamic network environment against evolving cyberthreats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Real-Time Network Intrusion Detection Using Hybrid Incremental Learning Approach

  • Sumedha Seniaray,
  • Rajni Jindal

摘要

In our gradual expansion of digital environments, where the growth of cyberattacks has become more frequent, the need for a real-time intrusion detection system (IDS) has become crucial. Traditional IDS models often fail to detect vulnerabilities in dynamically evolving networks, accentuating the need for adaptive solutions. Addressing this challenge, this paper proposes a novel hybrid incremental learning framework for anomaly-based intrusion detection called HIL-IDS. Initially, real-time packet sniffing and feature extraction using Scapy are executed to process raw network traffic. HIL-IDS integrates the Hoeffding tree for incremental supervised learning and an ensemble of isolation forest and KMeans for unsupervised anomaly detection. Confidence scores from the combination of these supervised and unsupervised models are evaluated to enhance the interpretability of the proposed framework. Drift detection is performed to preserve the robustness against the shifting data distributions of the real-time traffic and to adapt new emergent patterns. The proposed model is trained on the CSE-CIC-IDS2018 intrusion detection dataset, a comprehensive benchmark that includes modern attack types. Experimental results show that the proposed hybrid incremental learning approach-based IDS effectively acquires and adjusts to emerging attack patterns. It achieves the highest accuracy of 98.88%, maintaining real-time efficiency and an effective solution towards strengthening the dynamic network environment against evolving cyberthreats.