Synthetic attack data generation model applying generative adversarial network for intrusion detection. Issue 125 (February 2023)
- Record Type:
- Journal Article
- Title:
- Synthetic attack data generation model applying generative adversarial network for intrusion detection. Issue 125 (February 2023)
- Main Title:
- Synthetic attack data generation model applying generative adversarial network for intrusion detection
- Authors:
- Kumar, Vikash
Sinha, Ditipriya - Abstract:
- Abstract : Detecting a large number of attack classes accurately applying machine learning (ML) and deep learning (DL) techniques depends on the number of representative samples available for each attack class. In most cases, the data samples are highly imbalanced that results in a biased intrusion detection model towards the majority classes. Under-sampling, over-sampling and SMOTE are some techniques among the solutions that turn the imbalanced dataset to balanced one. These techniques have not had much impact on the improvement of detection accuracy. To deal with this problem, this paper proposes a Wasserstein Conditional Generative Adversarial Network (WCGAN) combined with an XGBoost Classifier. Gradient penalty along with the WCGAN is used for stable learning of the model. The proposed model is evaluated with some other GAN models (i.e., standard/vanilla GAN, Conditional GAN) which shows the significance of applying WCGAN in this paper. The loss on generated and real data shows a similar pattern and is lower for the Wasserstein variants of GAN compared to the other variants of the GAN model. The performance is benchmarked on three datasets NSL-KDD, UNSW-NB15 and BoT-IoT. The comparison of performance metrics before and after using the proposed framework with XGBoost classifier shows improvement in terms of higher precision, recall and F-1 score. However, comparatively less improvement is observed in FAR compared to other classifiers such as Random Forest (RF), DecisionAbstract : Detecting a large number of attack classes accurately applying machine learning (ML) and deep learning (DL) techniques depends on the number of representative samples available for each attack class. In most cases, the data samples are highly imbalanced that results in a biased intrusion detection model towards the majority classes. Under-sampling, over-sampling and SMOTE are some techniques among the solutions that turn the imbalanced dataset to balanced one. These techniques have not had much impact on the improvement of detection accuracy. To deal with this problem, this paper proposes a Wasserstein Conditional Generative Adversarial Network (WCGAN) combined with an XGBoost Classifier. Gradient penalty along with the WCGAN is used for stable learning of the model. The proposed model is evaluated with some other GAN models (i.e., standard/vanilla GAN, Conditional GAN) which shows the significance of applying WCGAN in this paper. The loss on generated and real data shows a similar pattern and is lower for the Wasserstein variants of GAN compared to the other variants of the GAN model. The performance is benchmarked on three datasets NSL-KDD, UNSW-NB15 and BoT-IoT. The comparison of performance metrics before and after using the proposed framework with XGBoost classifier shows improvement in terms of higher precision, recall and F-1 score. However, comparatively less improvement is observed in FAR compared to other classifiers such as Random Forest (RF), Decision Tree (DT), Support Vector Machine (SVM). The proposed work is also compared with a recent similar technique called DGM, which uses conditional GAN along with different ML classification models. The performance of the proposed model outperforms DGM. The proposed model creates a significant footprint (or, attack signatures) to tackle with the problem of data-imbalance during the design of the Intrusion Detection System (IDS). … (more)
- Is Part Of:
- Computers & security. Issue 125(2023)
- Journal:
- Computers & security
- Issue:
- Issue 125(2023)
- Issue Display:
- Volume 125, Issue 125 (2023)
- Year:
- 2023
- Volume:
- 125
- Issue:
- 125
- Issue Sort Value:
- 2023-0125-0125-0000
- Page Start:
- Page End:
- Publication Date:
- 2023-02
- Subjects:
- Intrusion detection system -- Cyber-attack -- Generative adversarial networks -- Data synthetization -- Data imbalance
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2022.103054 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 24838.xml