Network intrusion detection system with incremental active learning

2022-9-14
Bedir Tüzün, Münteha Nur
While Internet usage has increased every year, it has gained momentum in recent years with the global pandemic. Increasing Internet usage has brought increasing cyber threats. Intrusion detection systems have become more important than ever. The performance of these systems is directly proportional to their adaptiveness to the rapid changes in attack types. However, desired performance cannot always be achieved due to the lack of labeled data on newly developed attacks and the difficulty of incremental learning with machine learning methods. In this study, we proposed a network intrusion detection system using active learning methods for class incremental learning, which can adapt to the dynamic environment and provide high performance with less labeled data. Experiment results show that the proposed method requires fewer labeled training data instances and learns new types of attacks incrementally.

Suggestions

Explainable Security in SDN-Based IoT Networks
Sarica, Alper Kaan; Angın, Pelin (2020-12-01)
The significant advances in wireless networks in the past decade have made a variety of Internet of Things (IoT) use cases possible, greatly facilitating many operations in our daily lives. IoT is only expected to grow with 5G and beyond networks, which will primarily rely on software-defined networking (SDN) and network functions virtualization for achieving the promised quality of service. The prevalence of IoT and the large attack surface that it has created calls for SDN-based intelligent security solut...
NETWORK INTRUSION DETECTION WITH A DEEP LEARNING APPROACH
Kültür, Ebru; Acar, Aybar Can; Department of Cybersecurity (2022-2-7)
With the rapid growth of the information technology in several areas, providing security of those systems has gained more importance. As a result of this development in information technology, the complexity of cyber-attacks has also significantly increased. Therefore, traditional security tools such as Signature-based Intrusion Detection Systems (SIDS) have become insufficient for detecting new attacks. Intrusion Detection Systems (IDS) are used to monitor network traffic and capture malicious traffic. Tra...
Use of Social Media across Different Generations in Higher Education in a Developing Country
Celik, Ilknur; Schoreels, Cyril (2014-09-20)
While social media is increasing its extent and reach every day, research shows that its impact seems to be more intense in developing countries for various reasons. In developing countries, social media not only satisfies personal communication needs but also tends to compete with mainstream media for news and play a significant role in social movements. Hence potential use of this mounting medium for education needs to be explored. In this study, a social media and education survey has been prepared in or...
Level of imposition and explicit electronic apologies
Hatipoğlu, Çiler (Wesbaden: Harassowitz Verlag; 2009-03-01)
In the last few decades the number of the world’s population online has increased rapidly and now it is more than one billion (Internet World Stats 2007). The meaning of this development is that every day more and more people start to use the so called internet/electronic language both for business and personal interactions. This rapid progress brings, however, a number of problems for linguists as well as the general public since with the introduction of the new medium,...
Network attack classification with few-shot learning methods
Tüzün, İsmail; Angın, Pelin; Department of Computer Engineering (2022-9-14)
As the number of devices using the Internet increases, the network attacks that these devices are exposed to also diversify. Identifying network attack types from network packets is important to prevent the damage of the attack and to minimize it in cases where it cannot be prevented. Classical machine learning methods and deep learning methods need a lot of data to get successful results. Unfortunately, preparing and labeling large amounts of data is costly in current conditions. This cost is mostly due to...
Citation Formats
M. N. Bedir Tüzün, “Network intrusion detection system with incremental active learning,” M.S. - Master of Science, Middle East Technical University, 2022.