On the Evaluation of Sequential Machine Learning for Network Intrusion Detection

dc.contributor.authorCorsini, Andrea
dc.contributor.authorYang, Shanchieh Jay
dc.contributor.authorApruzzese, Giovanni
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-24T13:55:01Z
dc.date.available2026-09-24T13:55:01Z
dc.date.issued2021-08-17
dc.descriptionPublisher Copyright: © 2021 ACM.en
dc.description.abstractRecent advances in deep learning renewed the research interests in machine learning for Network Intrusion Detection Systems (NIDS). Specifically, attention has been given to sequential learning models, due to their ability to extract the temporal characteristics of network traffic flows (NetFlows), and use them for NIDS tasks. However, the applications of these sequential models often consist of transferring and adapting methodologies directly from other fields, without an in-depth investigation on how to leverage the specific circumstances of cybersecurity scenarios; moreover, there is a lack of comprehensive studies on sequential models that rely on NetFlow data, which presents significant advantages over traditional full packet captures. We tackle this problem in this paper. We propose a detailed methodology to extract temporal sequences of NetFlows that denote patterns of malicious activities. Then, we apply this methodology to compare the efficacy of sequential learning models against traditional static learning models. In particular, we perform a fair comparison of a ĝ€sequential' Long Short-Term Memory (LSTM) against a ĝ€static' Feedforward Neural Networks (FNN) in distinct environments represented by two well-known datasets for NIDS: the CICIDS2017 and the CTU13. Our results highlight that LSTM achieves comparable performance to FNN in the CICIDS2017 with over 99.5% F1-score; while obtaining superior performance in the CTU13, with 95.7% F1-score against 91.5%. This paper thus paves the way to future applications of sequential learning models for NIDS.en
dc.description.versionPeer revieweden
dc.format.extent974354
dc.format.extent
dc.format.extent
dc.identifier.citationCorsini, A, Yang, S J & Apruzzese, G 2021, On the Evaluation of Sequential Machine Learning for Network Intrusion Detection. in 16th International Conference on Availability, Reliability and Security, ARES 2021., 3470065, ACM International Conference Proceeding Series, Association for Computing Machinery, 16th International Conference on Availability, Reliability and Security, ARES 2021, Virtual, Online, Austria, 17/08/21. https://doi.org/10.1145/3465481.3470065en
dc.identifier.citationconferenceen
dc.identifier.doi10.1145/3465481.3470065
dc.identifier.isbn9781450390514
dc.identifier.other250863734
dc.identifier.other7bca992d-623b-40be-9d78-2f11e580ff8f
dc.identifier.other85113232575
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8355
dc.language.isoen
dc.publisherAssociation for Computing Machinery
dc.relation.ispartofseries16th International Conference on Availability, Reliability and Security, ARES 2021; ()en
dc.relation.ispartofseriesACM International Conference Proceeding Series; ()en
dc.relation.urlhttps://www.scopus.com/pages/publications/85113232575en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectCybersecurityen
dc.subjectDeep Learningen
dc.subjectLong Short Term Memoryen
dc.subjectMachine Learningen
dc.subjectNetwork Flowsen
dc.subjectNetwork Intrusion Detectionen
dc.subjectSoftwareen
dc.subjectHuman-Computer Interactionen
dc.subjectComputer Vision and Pattern Recognitionen
dc.subjectComputer Networks and Communicationsen
dc.titleOn the Evaluation of Sequential Machine Learning for Network Intrusion Detectionen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conferenceen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
3465481.3470065.pdf
Stærð:
951.52 KB
Snið:
Adobe Portable Document Format