AIセキュリティポータル K Program
SoK: Pragmatic Assessment of Machine Learning for Network Intrusion Detection
Share
Abstract
Machine Learning (ML) has become a valuable asset to solve many real-world tasks. For Network Intrusion Detection (NID), however, scientific advances in ML are still seen with skepticism by practitioners. This disconnection is due to the intrinsically limited scope of research papers, many of which primarily aim to demonstrate new methods ``outperforming'' prior work -- oftentimes overlooking the practical implications for deploying the proposed solutions in real systems. Unfortunately, the value of ML for NID depends on a plethora of factors, such as hardware, that are often neglected in scientific literature. This paper aims to reduce the practitioners' skepticism towards ML for NID by "changing" the evaluation methodology adopted in research. After elucidating which "factors" influence the operational deployment of ML in NID, we propose the notion of "pragmatic assessment", which enable practitioners to gauge the real value of ML methods for NID. Then, we show that the state-of-research hardly allows one to estimate the value of ML for NID. As a constructive step forward, we carry out a pragmatic assessment. We re-assess existing ML methods for NID, focusing on the classification of malicious network traffic, and consider: hundreds of configuration settings; diverse adversarial scenarios; and four hardware platforms. Our large and reproducible evaluations enable estimating the quality of ML for NID. We also validate our claims through a user-study with security practitioners.
Deep learning-enabled medical computer vision
A. Esteva
Published: 2021
Machine learning at Facebook: Understanding inference at the edge
C.-J. Wu
Published: 2019
A survey of the usages of deep learning for natural language processing
Daniel W Otter, Julian R Medina, Jugal K Kalita
Published: 2020
Deep Speech 2: End-to-end speech recognition in English and Mandarin
D. Amodei
Published: 2016
A survey on deep learning in medical image analysis
G. Litjens, et al.
Published: 2017
Applicability of machine learning in spam and phishing email filtering: review and approaches
T. Gangavarapu
Published: 2020
Dos and Don'ts of Machine Learning in Computer Security
Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, Konrad Rieck
Published: 10.19.2020
Information Security Analysis as Data Fusion
M. De Shon
Published: 2019
Security Operations Center (SOC)
Published: 2021
99% false positives: A qualitative study of SOC analysts’ perspectives on security alarms
Bushra A Alahmadi, Louise Axon, Ivan Martinovic
Published: 2022
Anomaly detection of web-based attacks
C. Kruegel, G. Vigna
Published: 2003
Anagram: A content anomaly detector resistant to mimicry attack
K. Wang
Published: 2006
Language models for detection of unknown attacks in network traffic
K. Rieck, P. Laskov
Published: 2007
Outside the closed world: On using machine learning for network intrusion detection
R. Sommer, V. Paxson
Published: 2010
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L. Li, K. Li, L. Fei-Fei
Published: 2009
ImageNet training in minutes
Y. You
Published: 2018
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
Improved knowledge distillation via teacher assistant
S. I. Mirzadeh
Published: 2020
Drebin: Effective and explainable detection of android malware in your pocket
D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, K. Rieck
Published: 2014
Can we leverage predictive uncertainty to detect dataset shift and adversarial examples in android malware detection?
D. Li
Published: 2021
Less is more: A privacy-respecting android malware classifier using federated learning
R. Galvez
Published: 2021
The duplication issue within the DREBIN dataset
P. Irolla, A. Dey
Published: 2018
Eight years of rider measurement in the android malware ecosystem
G. Suarez-Tangil, G. Stringhini
Published: 2020
A deep dive inside drebin: An explorative analysis beyond android malware detection scores
Nadia Daoudi, Kevin Allix, Tegawende François Bissyandé, Jacques Klein
Published: 2022
A detailed investigation and analysis of using machine learning techniques for intrusion detection
P. Mishra, V. Varadharajan, U. Tupakula, E. S. Pilli
Published: 2019
The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems
Giovanni Apruzzese, Luca Pajola, Mauro Conti
Published: 3.9.2022
Netflow datasets for machine learning-based network intrusion detection systems
M. Sarhan
Published: 2021
Toward generating a new intrusion detection dataset and intrusion traffic characterization
Iman Sharafaldin, Arash Habibi Lashkari, Ali A Ghorbani
Published: 2018
Deep learning approach for intelligent intrusion detection system
R. Vinayakumar, M. Alazab, K. Soman, P. Poornachandran, A. Al-Nemrat, S. Venkatraman
Published: 2019
A new method for flow-based network intrusion detection using the inverse potts model
C. Pontes
Published: 2021
Troubleshooting an intrusion detection dataset: the cicids2017 case study
G. Engelen, V. Rimmer, W. Joosen
Published: 2021
INSOMNIA: towards concept-drift robustness in network intrusion detection
G. Andresini, F. Pendlebury, F. Pierazzi, C. Loglisci, A. Appice, L. Cavallaro
Published: 2021
Security in mobile ad hoc networks: challenges and solutions
H. Yang
Published: 2004
Intrusion detection system: A comprehensive review
H.-J. Liao, C.-H. Richard Lin, Y.-C. Lin, K.-Y. Tung
Published: 2013
LEoNIDS: A low-latency and energy-efficient network-level intrusion detection system
N. Tsikoudis
Published: 2014
Internet security glossary, version 2
R. Shirey
Published: 2007
Network intrusion detection
B. Mukherjee
Published: 1994
A survey on data-driven network intrusion detection
D. Chou, M. Jiang
Published: 2021
Enabling visual analytics via alert-driven attack graphs
A. Nadeem
Published: 2021
Network Intrusion Detection for IoT security based on learning techniques
N. Chaabouni
Published: 2019
Spear SIEM: A security information and event management system for the smart grid
P. Radoglou-Grammatikis
Published: 2021
Improving SIEM alert metadata aggregation with a novel kill-chain based classification model
B. D. Bryant, H. Saiedian
Published: 2020
Made: Security analytics for enterprise threat detection
A. Oprea
Published: 2018
A user-centric machine learning framework for cyber security operations center
C. Feng
Published: 2017
Survey of intrusion detection systems: techniques, datasets, and challenges
Khraisat, A., et al.
Published: 2019
Network Anomaly Detection Using Transfer Learning Based on Auto-Encoders Loss Normalization
A. Yehezkel
Published: 2021
Near-real-time Anomaly Detection in Encrypted Traffic using Machine Learning Techniques
D. Ucci
Published: 2021
Why are my flows different? a tutorial on flow exporters
G. Vormayr, J. Fabini, T. Zseby
Published: 2020
On the evaluation of sequential machine learning for network intrusion detection
A. Corsini
Published: 2021
A Framework for Cluster and Classifier Evaluation in the Absence of Reference Labels
R. J. Joyce
Published: 2021
A survey of data mining and machine learning methods for cyber security intrusion detection
A. L. Buczak, E. Guven
Published: 2016
On the effectiveness of machine and deep learning for cybersecurity
G. Apruzzese
Published: 2018
Machine learning and deep learning methods for intrusion detection systems: A survey
Liu, H., Lang, B.
Published: 2019
A survey of network-based intrusion detection data sets
Ring, M., Wunderlich, S., Scheuring, D., Landes, D., Hotho, A.
Published: 2019
Identifying malicious hosts involved in periodic communications
G. Apruzzese
Published: 2017
Deepcase: Semi-supervised contextual analysis of security events
T. Van Ede
Published: 2022
Realistic evaluation of deep semi-supervised learning algorithms
Avital Oliver, Augustus Odena, Colin A Raffel, Ekin Dogus Cubuk, Ian Goodfellow
Published: 2018
Key concepts in cyber security: Towards a common policy and technology context for cyber security norms
C. Vishik
Published: 2016
Some fundamental cybersecurity concepts
K. S. Wilson, M. A. Kiy
Published: 2014
Economics of artificial intelligence in cybersecurity
N. Kshetri
Published: 2021
Stakeholder perspectives and requirements on cybersecurity in Europe
S. Fischer-Hubner
Published: 2021
A security monitoring plane for named data networking deployment
T. Nguyen
Published: 2018
Machine Learning in the Age of Cyber AI
Published: 2020
Using AI to detect and contain Cyberthreats
Published: 2019
One-class classification: Concept learning in the absence of counter-examples
D. M. J. Tax
Published: 2002
The economics of cybersecurity: Principles and policy options
T. Moore
Published: 2010
Modeling realistic adversarial attacks against network intrusion detection systems
G. Apruzzese, M. Andreolini, L. Ferretti, M. Marchetti, M. Colajanni
Published: 2022
Challenges in deploying machine learning: a survey of case studies
A. Paleyes
Published: 2022
Towards the deployment of machine learning solutions in network traffic classification: A systematic survey
F. Pacheco, E. Exposito, M. Gineste, C. Baudoin, J. Aguilar
Published: 2018
The Role of Machine Learning in Cybersecurity
Giovanni Apruzzese, Pavel Laskov, Edgardo Montes de Oca, Wissam Mallouli, Luis Burdalo Rapa, Athanasios Vasileios Grammatopoulos, Fabio Di Franco
Published: 6.20.2022
Transcend: Detecting concept drift in malware classification models
R. Jordaney, K. Sharad, S. K. Dash, Z. Wang, D. Papini, I. Nouretdinov, L. Cavallaro
Published: 2017
Adversarial attacks against intrusion detection systems: Taxonomy, solutions and open issues
I. Corona, G. Giacinto, F. Roli
Published: 2013
Requirements engineering for machine learning: Perspectives from data scientists
A. Vogelsang
Published: 2019
SoK: The Impact of Unlabelled Data in Cyberthreat Detection
Giovanni Apruzzese, Pavel Laskov, Aliya Tastemirova
Published: 5.18.2022
Classification in the presence of label noise: a survey
B. Frenay, M. Verleysen
Published: 2013
Network Intrusion Detection and Comparative Analysis using Ensemble Machine Learning and Feature Selection
S. Das
Published: 2021
One-and-a-half-class multiple classifier systems for secure learning against evasion attacks at test time
B. Biggio
Published: 2015
An efficient cascaded method for network intrusion detection based on extreme learning machines
Y. Yu
Published: 2018
Internet of things: A survey on machine learning-based intrusion detection approaches
K. A. Da Costa, J. P. Papa, C. O. Lisboa, R. Munoz, V. H. C. de Albuquerque
Published: 2019
AI-IDS: Application of deep learning to real-time Web intrusion detection
A. Kim
Published: 2020
Reviewer Integration and Performance Measurement for Malware Detection
Brad Miller, Alex Kantchelian, Michael Carl Tschantz, Sadia Afroz, Rekha Bachwani, Riyaz Faizullabhoy, Ling Huang, Vaishaal Shankar, Tony Wu, George Yiu, Anthony D. Joseph, J. D. Tygar
Published: 10.26.2015
FP-ELM: An online sequential learning algorithm for dealing with Concept Drift
D. Liu
Published: 2016
Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning
Battista Biggio, Fabio Roli
Published: 12.9.2017
Identifying challenges to the certification of machine learning for safety critical systems
E. Jenn
Published: 2020
Open-world network intrusion detection
V. Rimmer
Published: 2022
On Artificial Intelligence—A European approach to excellence and trust
Published: 2020
Cost-efficient overclocking in immersion-cooled datacenters
M. Jalili
Published: 2021
Dictionary extraction and detection of algorithmically generated domain names in passive dns traffic
M. Pereira
Published: 2018
Share