Mateen: adaptive ensemble learning for network anomaly detection
File(s) 3678890.3678901.pdf (1.42 MB)
Published version
Author(s)
Alotaibi, Fahad
Maffeis, Sergio
Type
Conference Paper
Abstract
Anomaly-based intrusion detection systems are tasked with identifying deviations from established benign network behaviors, assuming such deviations to be indicators of malicious intent. Deep AutoEncoders (DAEs) have become increasingly popular in these systems due to their exceptional ability to model benign behavior with high accuracy, particularly in static, offline settings where the network’s benign activity pattern is presumed to remain constant. However, this static approach becomes less effective as network behavior naturally evolves, leading to challenges in distinguishing new, benign activities from genuine threats. This evolution raises a critical question: How can we enhance offline DAEs to accurately identify threats while avoiding false alarms caused by benign behavior changes?
To address this question, we propose Mateen, an online learning framework designed to augment the capabilities of offline DAEs, enabling them to recognize and adapt to changing benign network behaviors efficiently and with minimal overhead. Mateen leverages an ensemble of DAEs to monitor and adjust to these changes. It optimizes resource usage by selecting only a few representative samples for updates and reduces the overall framework’s complexity by retaining only the relevant models.
We evaluate the effectiveness of Mateen on five network intrusion datasets, each exhibiting different types of benign behavior evolution. The results demonstrate that Mateen consistently enhances offline DAE performance across various evolution types. For instance, Mateen boosts the F1-score on the IDS17 dataset, which exhibits light change, by 4.13%, and on the Kitsune dataset, characterized by heavy change, by 72.6%, while only necessitating labeling for 1% of the incoming samples.
To address this question, we propose Mateen, an online learning framework designed to augment the capabilities of offline DAEs, enabling them to recognize and adapt to changing benign network behaviors efficiently and with minimal overhead. Mateen leverages an ensemble of DAEs to monitor and adjust to these changes. It optimizes resource usage by selecting only a few representative samples for updates and reduces the overall framework’s complexity by retaining only the relevant models.
We evaluate the effectiveness of Mateen on five network intrusion datasets, each exhibiting different types of benign behavior evolution. The results demonstrate that Mateen consistently enhances offline DAE performance across various evolution types. For instance, Mateen boosts the F1-score on the IDS17 dataset, which exhibits light change, by 4.13%, and on the Kitsune dataset, characterized by heavy change, by 72.6%, while only necessitating labeling for 1% of the incoming samples.
Date Issued
2024-09
Date Acceptance
2024-06-24
Citation
RAID '24: Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses, 2024, pp.215-234
ISBN
979-8-4007-0959-3
Publisher
ACM
Start Page
215
End Page
234
Journal / Book Title
RAID '24: Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses
Copyright Statement
Copyright © 2024 Owner/Author.
This work is licensed under a Creative Commons Attribution International 4.0 License.
This work is licensed under a Creative Commons Attribution International 4.0 License.
License URL
Identifier
https://dl.acm.org/doi/10.1145/3678890.3678901
Source
International Symposium on Research in Attacks, Intrusions and Defenses (RAID)
Subjects
Computer Security
Machine Learning
Unsupervised Machine Learning
Publication Status
Published
Start Date
2024-09-30
Finish Date
2024-10-02
Coverage Spatial
Padua, Italy
Date Publish Online
2024-09-30
