Which algorithm can detect unknown attacks? Comparison of supervised, unsupervised and meta-learning algorithms for intrusion detection. Issue 127 (April 2023)
- Record Type:
- Journal Article
- Title:
- Which algorithm can detect unknown attacks? Comparison of supervised, unsupervised and meta-learning algorithms for intrusion detection. Issue 127 (April 2023)
- Main Title:
- Which algorithm can detect unknown attacks? Comparison of supervised, unsupervised and meta-learning algorithms for intrusion detection
- Authors:
- Zoppi, Tommaso
Ceccarelli, Andrea
Puccetti, Tommaso
Bondavalli, Andrea - Abstract:
- Abstract: There is an astounding growth in the adoption of machine learners (MLs) to craft intrusion detection systems (IDSs). These IDSs model the behavior of a target system during a training phase, making them able to detect attacks at runtime. Particularly, they can detect known attacks, whose information is available during training, at the cost of a very small number of false alarms, i.e., the detector suspects attacks but no attack is actually threatening the system. However, the attacks experienced at runtime will likely differ from those learned during training and thus will be unknown to the IDS. Consequently, the ability to detect unknown attacks becomes a relevant distinguishing factor for an IDS. This study aims to evaluate and quantify such ability by exercising multiple ML algorithms for IDSs. We apply 47 supervised, unsupervised, deep learning, and meta-learning algorithms in an experimental campaign embracing 11 attack datasets, and with a methodology that simulates the occurrence of unknown attacks. Detecting unknown attacks is not trivial: however, we show how unsupervised meta-learning algorithms have better detection capabilities of unknowns and may even outperform classification performance of other ML algorithms when dealing with unknown attacks.
- Is Part Of:
- Computers & security. Issue 127(2023)
- Journal:
- Computers & security
- Issue:
- Issue 127(2023)
- Issue Display:
- Volume 127, Issue 127 (2023)
- Year:
- 2023
- Volume:
- 127
- Issue:
- 127
- Issue Sort Value:
- 2023-0127-0127-0000
- Page Start:
- Page End:
- Publication Date:
- 2023-04
- Subjects:
- Intrusion detection -- Machine learning -- Unknown attacks -- Unsupervised -- Meta-Learning -- Zero-Day attacks
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2023.103107 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 25984.xml