Empirical Study of Hierarchical Intrusion Detection Systems for Unknown Attacks

Menaka Pushpa Arthur, Ganesan Ramachandran, Keshav Sood, Pavan Kaarthik, Srivarshinee Sridhar, Morshed Chowdhury · IEEE Transactions on Network and Service Management · 2025

The attack detection models of the traditional Intrusion Detection Systems (IDSs) IDSsIntrusion Detection Systems are trained on closed-set problems which reduces the classifiers’ performance on detecting unknown attacks in the open-set problem space. Mostly adapted, one-short learning in the classifier does not allow the traditional IDS to be an open-set recognizer. The alternate continuous learning-based IDS in unknown attack detection claims ongoing suggestions from experts to retrain the model with newly identified samples. Hence, using the multi-layer hierarchical IDS (HIDS) HIDSHierarchical IDS with optimized classifier models, the unknown attacks can be classified by comparing their patterns with benign and known attacks. However, we have identified many challenges in the existing HIDS system on various datasets though it provides a solid foundation in this design category for unknown attack identification. As a result, in this paper, we designed an enhanced multi-tier IDS for zero-day attack detection with optimized heterogeneous classifiers in its major two phases like basic framework demands. We have examined the enhanced proposed hierarchical IDS on various benchmark Intrusion Detection Systems datasets such as WUSTL, CIC_IDS_2017, 5G and UNR to analyze the efficiency in unknown attacks classification. When compare to existing multi-tier IDS, the proposed IDS achieved highest detection 96.2%,87%,96.8% and 100% in 5G, WUSTL, UNR and CIC_IDS_2017 datasets for unknown attacks. The optimized model in the proposed IDS reduces the time complexity into 50% than the existing. Implementation results show the proposed enhanced IDS performs better than the existing hierarchical IDS with a high true positive rate for benign, known and unknown attack labels on various datasets.

Read the paper · More papers on PaperTik