Network Intrusion Detection Systems are essential tools for protecting networks against attacks. Deep Learning approaches are increasingly employed in developing these systems due to their versatility and effectiveness. However, the common procedure for training and testing Deep Learning models typically leverages traffic data entirely collected from the operational network managed by a single organization, posing privacy and security concerns in sharing these data. As a result, the assessment of the performance of these models in real-world scenarios is significantly hindered. On the other hand, given the wide variety of existing attacks and the emergence of new attack types, it is crucial to evaluate the robustness of Intrusion Detection Systems when the network context varies. Indeed, it is highly desirable that the effectiveness of trained Deep Learning models is not severely impacted when ported into other networks.To this aim, in this work, we exploit various single-modal and multimodal Deep Learning approaches and leverage a cross-evaluation procedure to assess their capability to distinguish malicious from benign traffic in different network contexts. Furthermore, we investigate the impact of various informative fields extracted from traffic on the generalization capability of models. Our cross-evaluation leverages three recent public-available network attack datasets related to diverse scenarios. The results obtained suggest that the availability at training time of traffic generated by attacks conducted in the operational network is crucial for designing a robust Intrusion Detection System that keeps working with minimal Fl-score degradation, when the network context changes.

The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems / Apruzzese, Giovanni; Pajola, Luca; Conti, Mauro. - In: IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT. - ISSN 1932-4537. - (2022), pp. N/A-N/A. (Intervento presentato al convegno 2023 10th International Conference on Future Internet of Things and Cloud (FiCloud) tenutosi a Marrakesh, Morocco. nel 14-16 Aug. 2023) [10.48550/arxiv.2203.04686].

The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems

Giovanni Apruzzese;Mauro Conti
2022

Abstract

Network Intrusion Detection Systems are essential tools for protecting networks against attacks. Deep Learning approaches are increasingly employed in developing these systems due to their versatility and effectiveness. However, the common procedure for training and testing Deep Learning models typically leverages traffic data entirely collected from the operational network managed by a single organization, posing privacy and security concerns in sharing these data. As a result, the assessment of the performance of these models in real-world scenarios is significantly hindered. On the other hand, given the wide variety of existing attacks and the emergence of new attack types, it is crucial to evaluate the robustness of Intrusion Detection Systems when the network context varies. Indeed, it is highly desirable that the effectiveness of trained Deep Learning models is not severely impacted when ported into other networks.To this aim, in this work, we exploit various single-modal and multimodal Deep Learning approaches and leverage a cross-evaluation procedure to assess their capability to distinguish malicious from benign traffic in different network contexts. Furthermore, we investigate the impact of various informative fields extracted from traffic on the generalization capability of models. Our cross-evaluation leverages three recent public-available network attack datasets related to diverse scenarios. The results obtained suggest that the availability at training time of traffic generated by attacks conducted in the operational network is crucial for designing a robust Intrusion Detection System that keeps working with minimal Fl-score degradation, when the network context changes.
2022
2023 10th International Conference on Future Internet of Things and Cloud (FiCloud)
Marrakesh, Morocco.
14-16 Aug. 2023
N/A
N/A
Apruzzese, Giovanni; Pajola, Luca; Conti, Mauro
The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems / Apruzzese, Giovanni; Pajola, Luca; Conti, Mauro. - In: IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT. - ISSN 1932-4537. - (2022), pp. N/A-N/A. (Intervento presentato al convegno 2023 10th International Conference on Future Internet of Things and Cloud (FiCloud) tenutosi a Marrakesh, Morocco. nel 14-16 Aug. 2023) [10.48550/arxiv.2203.04686].
File in questo prodotto:
File Dimensione Formato  
2203.04686v1.pdf

Open access

Tipologia: AAM - Versione dell'autore revisionata e accettata per la pubblicazione
Dimensione 1.75 MB
Formato Adobe PDF
1.75 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

Licenza Creative Commons
I metadati presenti in IRIS UNIMORE sono rilasciati con licenza Creative Commons CC0 1.0 Universal, mentre i file delle pubblicazioni sono rilasciati con licenza Attribuzione 4.0 Internazionale (CC BY 4.0), salvo diversa indicazione.
In caso di violazione di copyright, contattare Supporto Iris

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11380/1373443
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact