Unsupervised Machine Learning for Cybersecurity Anomaly Detection in Traditional and Software-Defined Networking Environments
Curtis Rookard, Anahita Khojandi · IEEE Transactions on Network and Service Management · 2024
Cybersecurity has become a field of increasing importance within the past years, with the National Academy of Engineering most recently designating securing cyberspace as one of the fourteen Grand Challenges in Engineering in the 21st Century. Henceforth, it is imperative to design a robust anomaly detection and response approach that can identify and mitigate anomalous Internet traffic. In this study, we present several unsupervised/semi-supervised machine learning models to combat prolific anomalous data on a computer network. Specifically, we employ five unsupervised machine learning models, including a Generative Adversarial Network (GAN), Deep Belief Network (DBN), Restricted Boltzmann Machine (RBM), One-Class Support Vector Machine (OCSVM), and Isolation Forest (I-Forest). We use these models separately and, when applicable, combined together to examine their anomaly detection performance on three prominent traditional networking datasets, namely the KDD-Cup 99, NSL-KDD, and CIC-IDS2017 dataset, and implement these models within a software-defined networking and industrial Internet-of-Things environment using the DNP3 intrusion detection dataset. Furthermore, we investigate the generalizability of the models across the two datasets. Our results suggest I-Forest and DBN overall perform better than other models in traditional and software-defined networking environments; our GAN manages to outperform some benchmark models on the CIC-IDS2017 dataset.