PTN-IDS: Prototypical Network Solution for the Few-shot Detection in Intrusion Detection Systems
Nadia Niknami, Vahid Mahzoon, Jie Wu · 2024
Local Area Networks (LANs), as interconnected networks, are susceptible to numerous security threats. Existing intrusion detection systems (IDS) heavily rely on large, fully-labeled datasets to have accurate detection, facing challenges when only a few malicious samples are available. In addition, previous studies have identified the deterioration of IDS’s performance when the test dataset deviates from the training dataset distribution. To mitigate these issues, we propose a Prototypical Network-based IDS within a meta-learning framework. Our method adopts a Few-Shot Learning (FSL) approach, aiming to distinguish and compare network traffic samples to classify them as either normal or malicious. Notably, our model not only identifies benign or malicious traffic but also accurately identifies the specific types of attacks. We evaluate the effectiveness of our approach in different scenarios for few-shot network intrusion detection using real-world network traffic data. Additionally, we conduct a comprehensive sensitivity analysis to assess the impact of key factors such as model hyperparameters, support set size, attack type distribution, and distance metrics within the prototypical network model.