Cargando…
Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation
The ever-increasing use of internet has opened a new avenue for cybercriminals, alarming the online businesses and organization to stay ahead of evolving thread landscape. To this end, intrusion detection system (IDS) is deemed as a promising defensive mechanism to ensure network security. Recently,...
Autores principales: | , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
PeerJ Inc.
2020
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7924711/ https://www.ncbi.nlm.nih.gov/pubmed/33816977 http://dx.doi.org/10.7717/peerj-cs.327 |
_version_ | 1783659147100684288 |
---|---|
author | Vaiyapuri, Thavavel Binbusayyis, Adel |
author_facet | Vaiyapuri, Thavavel Binbusayyis, Adel |
author_sort | Vaiyapuri, Thavavel |
collection | PubMed |
description | The ever-increasing use of internet has opened a new avenue for cybercriminals, alarming the online businesses and organization to stay ahead of evolving thread landscape. To this end, intrusion detection system (IDS) is deemed as a promising defensive mechanism to ensure network security. Recently, deep learning has gained ground in the field of intrusion detection but majority of progress has been witnessed on supervised learning which requires adequate labeled data for training. In real practice, labeling the high volume of network traffic is laborious and error prone. Intuitively, unsupervised deep learning approaches has received gaining momentum. Specifically, the advances in deep learning has endowed autoencoder (AE) with greater ability for data reconstruction to learn the robust feature representation from massive amount of data. Notwithstanding, there is no study that evaluates the potential of different AE variants as one-class classifier for intrusion detection. This study fills this gap of knowledge presenting a comparative evaluation of different AE variants for one-class unsupervised intrusion detection. For this research, the evaluation includes five different variants of AE such as Stacked AE, Sparse AE, Denoising AE, Contractive AE and Convolutional AE. Further, the study intents to conduct a fair comparison establishing a unified network configuration and training scheme for all variants over the common benchmark datasets, NSL-KDD and UNSW-NB15. The comparative evaluation study provides a valuable insight on how different AE variants can be used as one-class classifier to build an effective unsupervised IDS. The outcome of this study will be of great interest to the network security community as it provides a promising path for building effective IDS based on deep learning approaches alleviating the need for adequate and diverse intrusion network traffic behavior. |
format | Online Article Text |
id | pubmed-7924711 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2020 |
publisher | PeerJ Inc. |
record_format | MEDLINE/PubMed |
spelling | pubmed-79247112021-04-02 Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation Vaiyapuri, Thavavel Binbusayyis, Adel PeerJ Comput Sci Computer Networks and Communications The ever-increasing use of internet has opened a new avenue for cybercriminals, alarming the online businesses and organization to stay ahead of evolving thread landscape. To this end, intrusion detection system (IDS) is deemed as a promising defensive mechanism to ensure network security. Recently, deep learning has gained ground in the field of intrusion detection but majority of progress has been witnessed on supervised learning which requires adequate labeled data for training. In real practice, labeling the high volume of network traffic is laborious and error prone. Intuitively, unsupervised deep learning approaches has received gaining momentum. Specifically, the advances in deep learning has endowed autoencoder (AE) with greater ability for data reconstruction to learn the robust feature representation from massive amount of data. Notwithstanding, there is no study that evaluates the potential of different AE variants as one-class classifier for intrusion detection. This study fills this gap of knowledge presenting a comparative evaluation of different AE variants for one-class unsupervised intrusion detection. For this research, the evaluation includes five different variants of AE such as Stacked AE, Sparse AE, Denoising AE, Contractive AE and Convolutional AE. Further, the study intents to conduct a fair comparison establishing a unified network configuration and training scheme for all variants over the common benchmark datasets, NSL-KDD and UNSW-NB15. The comparative evaluation study provides a valuable insight on how different AE variants can be used as one-class classifier to build an effective unsupervised IDS. The outcome of this study will be of great interest to the network security community as it provides a promising path for building effective IDS based on deep learning approaches alleviating the need for adequate and diverse intrusion network traffic behavior. PeerJ Inc. 2020-12-07 /pmc/articles/PMC7924711/ /pubmed/33816977 http://dx.doi.org/10.7717/peerj-cs.327 Text en © 2020 Vaiyapuri and Binbusayyis https://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, reproduction and adaptation in any medium and for any purpose provided that it is properly attributed. For attribution, the original author(s), title, publication source (PeerJ Computer Science) and either DOI or URL of the article must be cited. |
spellingShingle | Computer Networks and Communications Vaiyapuri, Thavavel Binbusayyis, Adel Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
title | Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
title_full | Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
title_fullStr | Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
title_full_unstemmed | Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
title_short | Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
title_sort | application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation |
topic | Computer Networks and Communications |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7924711/ https://www.ncbi.nlm.nih.gov/pubmed/33816977 http://dx.doi.org/10.7717/peerj-cs.327 |
work_keys_str_mv | AT vaiyapurithavavel applicationofdeepautoencoderasanoneclassclassifierforunsupervisednetworkintrusiondetectionacomparativeevaluation AT binbusayyisadel applicationofdeepautoencoderasanoneclassclassifierforunsupervisednetworkintrusiondetectionacomparativeevaluation |