错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Efficient Complex Event Processing in Intrusion Detection System Using CNN-BiLSTM Model

  • Aditya Kumar Singh,
  • Sakshi Chauhan,
  • S. Sandosh

摘要

Intrusion detection systems (IDSs) are essential for protecting computer networks from malicious attacks. As digital guardians, intrusion detection systems (IDSs) must defend computer networks against malicious attacks. On the other hand, as opposed to using the normal signature of known attacks, conventional IDS fails in handling the unusual or unidentified attacks. Development of an innovative CNN-BiLSTM hybrid model based on real-time intrusion detection by employing complex event processing (CEP) is the new method presented in this paper. Think about it as a skilful and mysterious digital detective with the capability to spot both the known network attacks plus the ones that are new and yet to be discovered. It has the capacity to comprehend both the broad picture and the finest details of the network traffic, in a similar way to how a highly proficient detective might take the account of the where and when of an attack into consideration. This idea was developed by basing it on the CIC-IDS2017 dataset. This dataset can successfully identify multiple categories of attacks such as those that traditional methods of attack detection might have missed. The entries in the CEP will consist of the main information about these attacks, for instance, the source and the destination, and the time of the occurrence. This strategy is distinct in the sense of maintaining an unpredictable number of events or threats happening with nearly real-time reliability. Consequently, under this mixed strategy the CEP can be an effective tool for real-time intrusion detection. Furthermore, the proposed solution was compared with the random forest model as well. The random forest model can be considered to be superior to the other model, because it gave us higher accuracy in correctly recognising attacks.