A survey about self-adaptive anomaly-detection in software-defined systems
Matthias Weiß, Stefan Thich, Maurice Artelt, Michael Weyrich · 2024
The rise of software-defined automation systems is accompanied by an increase in interconnected services and networks. Among other implications, this leads to an expansion of the attack surface for cyber threats, which in turn can lead to significant security issues and financial losses. Against this background, this paper investigates the effectiveness of anomaly-based intrusion detection systems (IDS) for detecting and preventing new and evolving cyber threats. The paper especially considers the challenge of concept drift, which describes the phenomenon that the statistical properties of the network traffic or behavior patterns that an IDS is trying to detect change over time. To accomplish this, a comprehensive literature review, prioritizing recent studies since 2019, highlights the challenges of concept drift and the application of reinforcement learning in IDS. The results suggest that the integration of adaptive strategies and reinforcement learning in IDS enables significant improvements in anomaly detection.