Development of Anomaly-Based Intrusion Detection Scheme Using Deep Learning in Data Network
D.H. Raju, Sakshi Sawai, Shashank Gavel, Ajay Singh Raghuvanshi · 2021
The sudden growth of network technologies and their associated threats have made it crucial to develop various methods for effectively detecting network attacks. Intrusion detection is critical for network security due to increasing connection between computers. The rapid growth of network traffic recently led to a limited amount of information being processed by flow-based intrusion detection systems. In addition, the framework also incorporates anomaly-based methods that can detect unknown attacks. Our research work focuses on the detection of anomalous network traffic or intruders by means of deep learning methods from flow-based data. We have utilized three deep learning models and analyzed the results using a semi-balanced version of the CIC-IDS2017 and CSE-CIC-IDS2018 dataset. The performance of the models, namely, Fully Connected Network, Seq2Seq LSTM, and Autoencoder was measured using the conventional metrics. We present the addition of two new evaluation metrics - Matthews Correlation Coefficient and Cohen's Kappa Coefficient for judging the performance of the utilized schemes as the well-known traditional metrics failed to give any conclusive results. The experimental results proved that the stability and robustness of the deep learning models could be judged more accurately using our proposed evaluation metrics.