Evolution and advancements in intrusion detection systems: from traditional methods to deep learning and federated learning approaches
ACCENTS Transactions on Information Security · 2024
In the modern digital age, the security of network infrastructures is of paramount importance.The rapid proliferation of internet-connected devices and the increasing complexity of network environments have amplified the necessity for robust security mechanisms [1,2].Intrusion detection systems (IDS) play a vital role in safeguarding networks against malicious activities, unauthorized access, and cyberattacks [3][4][5].IDS monitor network traffic, analyze data for suspicious patterns, and alert administrators to potential security breaches, thereby acting as a critical line of defense in cybersecurity strategies [6,7].The evolution of IDS technology has been marked by significant advancements, beginning with traditional methods and progressing to sophisticated machine learning and deep learning approaches [8][9][10].Early IDS implementations were primarily signature-based, relying on predefined patterns of known threats to detect intrusions [7][8][9][10].*Author for correspondence While effective against known attacks, these systems were limited by their inability to identify novel threats and their susceptibility to high false-positive rates [6][7][8][9][10].Anomaly-based detection methods emerged as an improvement, leveraging statistical models and behavioral analysis to identify deviations from normal network activity.However, these approaches also faced challenges in accurately distinguishing between benign anomalies and actual threats [7][8][9][10][11][12].The advent of machine learning introduced a paradigm shift in IDS development.ML algorithms, with their ability to learn from data and improve over time, offered promising solutions for enhancing detection accuracy and reducing false positives.[11,12] Supervised learning techniques, such as decision trees (DT), support vector machine (SVM), and k-nearest neighbors (kNN), were applied to classify network traffic based on labeled training data.Unsupervised learning methods, including clustering and anomaly detection algorithms, enabled the identification of previously unknown attack patterns without the need for labeled data.Despite their advancements, traditional ML approaches still encountered