Adversarial Drift Detection in Intrusion Detection System

The recent intrusion detection systems based on machine learning generally assume that the intrusion traffic always satisfies stationary of statistics.However,this assumption is not always held when adversaries arbitrarily alter the distribution of traffic data,or develop new attack techniques,which...

Full description

Saved in:
Bibliographic Details
Main Authors: Yaguan Qian, Xiaohui Guan
Format: Article
Language:zho
Published: Beijing Xintong Media Co., Ltd 2015-03-01
Series:Dianxin kexue
Subjects:
Online Access:http://www.telecomsci.com/zh/article/doi/10.11959/j.issn.1000-0801.2015058/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:The recent intrusion detection systems based on machine learning generally assume that the intrusion traffic always satisfies stationary of statistics.However,this assumption is not always held when adversaries arbitrarily alter the distribution of traffic data,or develop new attack techniques,which may reduce the detection rate.To overcome this adversarial drift,a novel drift detection approach based on weighted Rényi distance was suggested.The experiment on KDD Cup99 shows that the weighted Rényi distance is able to perfectly detect the adversarial drift,and improve the intrusion detection rate by retraining the model.
ISSN:1000-0801