A Multi-stage based Approach for Zero-day Attack Detection

Simeng Li, Guogen Wan · 2024

Intrusion detection systems (IDS) have traditionally been effective for security monitoring. However, with the continuous advancement of digitalization, the number and variety of connected devices are increasing, leading to the emergence of new and unknown threats. Current IDS struggle to effectively detect zero-day attacks, allowing these threats to bypass detection and execute their malicious tasks.To address this issue, this paper proposes a new multi-stage intrusion detection method. In the first stage, residual networks are employed to distinguish between benign and abnormal samples. The second stage uses a random forest algorithm to identify known attack types, while the third stage differentiates zero-day attacks from other threats.Performance was evaluated using the publicly available benchmark datasets CIC-IDS-2017 and CIC-IDS-2018.The findings demonstrate that our proposed approach is not only capable of effectively identifying zero-day attacks but also achieves higher classification performance compared to existing methods. Additionally, the multi-stage approach reduces the consumption of computing resources and bandwidth. The optimal performance model, balancing the threshold set, correctly classified 92.7% of zero-day attacks (38 out of 41), while reducing bandwidth requirements by 71%.

Read the paper · More papers on PaperTik