SDAID: Towards a Hybrid Signature and Deep Analysis-based Intrusion Detection Method
Hoang V. Vo, Hoa Ngoc Nguyen, Tu N. Nguyen, Hanh P. Du · GLOBECOM 2022 - 2022 IEEE Global Communications Conference · 2022
Current Intrusion Detection Systems (IDSs), which rely on signature-based detection using a set of rules formed by the past inspection of traffic flows and their signature, fail to detect new threats and malware. In this paper, we advocate for a hybrid algorithm combining signature and deep learning, dubbed signature, and deep analysis-based intrusion detection (SDAID) algorithm. In particular, the SDAID algorithm is constituted by an ensemble learning model of Deep Neural Network and Extreme Gradient Boosting. In addition, we also handle the im-balanced training dataset to improve the prediction performance of SDAID. To validate the feasibility of the proposed SDAID, well-known datasets, including CSE-CIC-IDS2018 and NSL-KDD datasets, are employed to conduct rigorous experiments. The results indicate that the proposed deep learning analysis achieves an excellent F1-score of 99.93% and 99.62% with the CSE-CIC-IDS2018 and NSL-KDD datasets. It also performs better than related models using the same datasets.