Network Intrusion Detection System Based on Separable Convolution AutoEncoder with Long Short-Term Memory
Fulin Zhang · 2024
In recent years, Intrusion Detection System (IDS) that continuously detects, analyzed network traffic for signs of malicious activity by enabling prompt detection and response to potential security incidents. Traditional approaches IDS had faced several challenges which include high false positive rates, limited detection capability. Therefore, this research proposes Separable Convolution AutoEncoder-Long Short-Term Memory (SCAE-LSTM) for network intrusion detection system. Initially, data is taken from Canadian Institute for Cybersecurity Intrusion Detection System (CICIDS) 2018 dataset is preprocessed by using t-Distributed Stochastic Neighboring Embedding (t-SNE) which reduces effectively in high-dimensional network traffic data to a lower dimensional representation. Then, the features are extracted from preprocessed data by using Local Linear Embedding (LLE) which identified nonlinear structures and anomalies that indicated in the network intrusions. After that, classification is done by using SCAE to complex patterns and anomalies in traffic data. Finally, the network intrusions are detected by using LSTM which effectively improves accuracy, reduces false positives, enhances the overall robustness in intrusion detection system. The proposed SCAE-LSTM achieved better accuracy (0.9755), detection rate (0.9999), F1 value (0.9575) and false positive rate (0.0128) when compared with existing CNN-LSTM.