Robust unsupervised network intrusion detection with self-supervised masked context reconstruction. Issue 128 (May 2023)
- Record Type:
- Journal Article
- Title:
- Robust unsupervised network intrusion detection with self-supervised masked context reconstruction. Issue 128 (May 2023)
- Main Title:
- Robust unsupervised network intrusion detection with self-supervised masked context reconstruction
- Authors:
- Wang, Wei
Jian, Songlei
Tan, Yusong
Wu, Qingbo
Huang, Chenlin - Abstract:
- Abstract: Modern network intrusion detection systems always utilize deep learning to improve their intelligence and feature learning abilities. To overcome the difficulties of accessing a large amount of labeled data and achieve early warning, lots of intrusion detection systems focus on unsupervised anomaly detection methods. However, most unsupervised anomaly detection methods ignore the temporal context and anomaly contamination in network intrusion data, which leads to suboptimal detection results. By considering the above practical problems, we propose a robust unsupervised intrusion detection system, i.e, RUIDS, by introducing a masked context reconstruction module into a transformer-based self-supervised learning scheme. The self-supervised learning scheme is designed to learn the intrinsic relationship within temporal contexts. And the masked context reconstruction module can learn more robust representations which are less sensitive to anomaly contamination. Extensive experiments on four intrusion datasets are conducted to show the effectiveness and robustness of RUIDS. Specifically, RUIDS achieves 9.04% and 9.58% improvements over the second-best method on the UNSW-NB15 and CICIDS-WED datasets in terms of AUC value respectively. We also test the robustness of our method with different anomaly contamination ratios, and our algorithm's performance has hardly decreased. The ablation study confirmed the effectiveness of the self-supervised learning scheme and theAbstract: Modern network intrusion detection systems always utilize deep learning to improve their intelligence and feature learning abilities. To overcome the difficulties of accessing a large amount of labeled data and achieve early warning, lots of intrusion detection systems focus on unsupervised anomaly detection methods. However, most unsupervised anomaly detection methods ignore the temporal context and anomaly contamination in network intrusion data, which leads to suboptimal detection results. By considering the above practical problems, we propose a robust unsupervised intrusion detection system, i.e, RUIDS, by introducing a masked context reconstruction module into a transformer-based self-supervised learning scheme. The self-supervised learning scheme is designed to learn the intrinsic relationship within temporal contexts. And the masked context reconstruction module can learn more robust representations which are less sensitive to anomaly contamination. Extensive experiments on four intrusion datasets are conducted to show the effectiveness and robustness of RUIDS. Specifically, RUIDS achieves 9.04% and 9.58% improvements over the second-best method on the UNSW-NB15 and CICIDS-WED datasets in terms of AUC value respectively. We also test the robustness of our method with different anomaly contamination ratios, and our algorithm's performance has hardly decreased. The ablation study confirmed the effectiveness of the self-supervised learning scheme and the masked context reconstruction module. … (more)
- Is Part Of:
- Computers & security. Issue 128(2023)
- Journal:
- Computers & security
- Issue:
- Issue 128(2023)
- Issue Display:
- Volume 128, Issue 128 (2023)
- Year:
- 2023
- Volume:
- 128
- Issue:
- 128
- Issue Sort Value:
- 2023-0128-0128-0000
- Page Start:
- Page End:
- Publication Date:
- 2023-05
- Subjects:
- Network intrusion detection -- Unsupervised learning -- Self-supervised learning -- Temporal context -- Anomaly detection
RUIDS the robust unsupervised intrusion detection system
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2023.103131 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 26785.xml