Investigating Domain Adaptation for Network Intrusion Detection

Hamza Alami, Meryem Janati Idrissi, Abdelkader El Mahdaouy, Abdelhak Bouayad, Zakaria Yartaoui, Ismaïl Berrada · 2023

With the ever-increasing network intrusion techniques, the effectiveness of conventional Network Intrusion Detection Systems (NIDS) solutions has become limited. As a response, machine learning-based NIDS have emerged as a potential alternative to handle newly designed intrusions. However, developing NIDS using machine learning methods necessitates high-quality labeled datasets, which can be time-consuming and resource-intensive. In this paper, we propose and assess a domain adaptation method specifically designed for NIDS. Initially, we represent flows as images using raw packets and NFStream. Next, we utilize convolutional neural networks to extract relevant features and employ gradient reversal for domain adaptation. This allows us to leverage a labeled dataset (source domain) to construct models that perform well on an unlabeled dataset (target domain). To assess the performance of our approach, we leverage suitable evaluation metrics and three publicly available datasets, namely USTC-TC2016, CIC-IDS2017, and CUPID. The results obtained indicate the need for further investigation into domain adaptation techniques for NIDS, potentially leading to improved intrusion detection capabilities.

Read the paper · More papers on PaperTik