NF-NIDS: Normalizing Flows for Network Intrusion Detection Systems

Meryem Janati Idrissi, Hamza Alami, Abdelhak Bouayad, Ismaïl Berrada · 2023

The rising frequency and complexity of cyber threats have necessitated the development of effective Network Intrusion Detection Systems (NIDS). Anomaly-based detection approaches have gained prominence for their ability to detect unknown and sophisticated attacks. In this paper, we introduce NF-NIDS, a novel approach for anomaly-based network intrusion detection using Normalizing Flows (NFs) to accurately classify network traffic into normal or malicious categories given the assumption of the availability of scarce attack samples. To address the challenge of limited attack samples, we employ two flow-based models, namely Inverse Autoregressive Flow (IAF) and Neural Spline Flows (NSF). These models are used to learn the underlying distribution of normal traffic and generate pseudo-attacks from the tails of the distribution. To evaluate the effectiveness of NF-NIDS, we conducted experiments on three well-known network datasets. The results demonstrate that our approach achieves high performance levels while incurring low to negligible false discovery rates. Specifically, NF-NIDS yields impressive results, with an accuracy of 98.71% for USTC-TFC2016, 94.86% for CIC-IDS2017, and 98.20% for CIC-IDS2018. In terms of the F1-score, NF-NIDS scores 98.72% for USTC-TFC2016, 97.05% for CIC-IDS2017, and 99.51% for CIC-IDS2018.

Read the paper · More papers on PaperTik