Leveraging the Training Data Partitioning to Improve Events Characterization in Intrusion Detection Systems

Saia R.
;
Carta S.;Fenu G.;Pompianu L.
2023-01-01

Abstract

The ever-increasing use of services based on computer networks, even in crucial areas unthinkable until a few years ago, has made the security of these networks a crucial element for anyone, also in consideration of the increasingly sophisticated techniques and strategies available to attackers. In this context, Intrusion Detection Systems (IDSs) play a primary role since they are responsible for analyzing and classifying each network activity as legitimate or illegitimate, allowing us to take the necessary countermeasures at the appropriate time. However, these systems are not infallible due to several reasons, the most important of which are the constant evolution of the attacks (e.g., zero-day attacks) and the problem that many of the attacks have behavior similar to those of legitimate activities, and therefore they are very hard to identify. This work relies on the hypothesis that the subdivision of the training data used for the IDS classification model definition into a certain number of partitions, in terms of events and features, can improve the characterization of the network events, improving the system performance. The non-overlapping data partitions train independent classification models, classifying the event according to a majority-voting rule. A series of experiments conducted on a benchmark real-world dataset support the initial hypothesis, showing a performance improvement with respect to a canonical training approach.
2023
Inglese
14
6
1345
1353
9
https://www.jait.us/show-233-1448-1.html
https://www.jait.us/list-225-1.html
Comitato scientifico
internazionale
scientifica
intrusion detection; network security; training data; algorithm
no
Saia, R.; Carta, S.; Fenu, G.; Pompianu, L.
1.1 Articolo in rivista
info:eu-repo/semantics/article
1 Contributo su Rivista::1.1 Articolo in rivista
262
4
open
Files in This Item:
File Size Format  
JAIT-V14N6-1345.pdf

open access

Type: versione editoriale
Size 1.67 MB
Format Adobe PDF
1.67 MB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie