Towards Effective Network Intrusion Detection in Imbalanced Datasets: A Hierarchical Approach
Md. Shamim Towhid, Nasik Sami Khan, Md Mahibul Hasan, Nashid Shahriar · 2024
The transition from conventional networks to Soft-ware Defined Networks (SDNs) has revolutionized network man-agement and control, but it also creates a huge security risk, underscoring the significance of effective intrusion detection systems (IDS). Researchers have used deep learning for IDS due to its ability to capture complex patterns in data. Deep Learning techniques rely on ample balanced labeled data for effective intrusion detection, but acquiring such balanced data in real network scenarios is a formidable challenge, often resulting in suboptimal performance for existing methods when dealing with imbalanced datasets. This paper introduces a hierarchical approach that is capable of effectively detecting well-known network attacks in an SDN environment, even with minimal training data. Our model, leveraging a dataset collected from a real-world software-defined wide area network (SD-WAN) environment, showcases remarkable adaptability by maintaining strong performance even with highly imbalanced data, i.e., attack samples with as few as 8 or 16 instances to others with hundreds, thousands, or even millions of instances. It consistently achieves an overall average F1 score above 92%, with minority class average F1 score reaching more than 84%, marking a substantial 22.50% performance improvement compared to selected base-lines in our evaluation.