An Approach to Multi-Class Intrusion Detection Based on Feature Subspaces and Weighted Fusion

Rui Liu, Yaokai Feng, Kouichi Sakurai · 2024

With the rapid proliferation of the users and the devices in the Internet, various types of cyber-attacks have become more frequent and sophisticated, making efficient attack detection systems increasingly indispensable. In many real-world scenarios, it is important to determine the specific categories of the attacks in order to take corresponding measures. Although many methods have been proposed to implement multi-class detection, most related works attempt to use one model which can output different results corresponding to different attacks, but the same input features are used for detecting different attack classes which can be a potential problem. Of course, the naive method is to build an independent classifier for each class of attacks. Several problems, however, would deteriorate the detection performance. For example, different attacks may increase the false positive alerts of the classifiers for each other and one attack may trigger alerts from different classifiers, as verified in our experiments. The possible reasons for this include the correlation of the different attacks and the inherent false positive rate of the classifiers. In this study, we propose a mechanism based on feature subspaces and weighted fusion for multi-class intrusion detection. Firstly, one classifier is built for each attack class based on feature subspace. Unlike the traditional methods, these classifiers does not simply report “positive” or “denign” for the corresponding attack class. Instead, each classifier reports one score for every attack class, indicating the “likelihood” that the input data belongs to that attack class. Subsequently, a weighted fusion process will make the final decision according to all the scores from the classifiers. Experimental result shows that our proposal clearly outperforms existing methods.

Read the paper · More papers on PaperTik