Open-Set Intrusion Detection with MinMax Autoencoder and Pseudo Extreme Value Machine

Guolou Ping,Xiaojun Ye
DOI: https://doi.org/10.1109/ijcnn55064.2022.9892858
2022-01-01
Abstract:The constant emergence of previously unseen applications and network attacks on the ever-changing Internet poses a serious challenge to traditional intrusion detection solutions. This paper aims to develop an intrusion detection system capable of distinguishing between past seen malicious and benign behaviors and inferring unseen ones. We formulate the problem of seen/unseen intrusion detection as an openset detection problem for known malicious, known benign and unknown behaviors, where unknown ones include both unseen malicious and benign behaviors. Subsequently, we propose an open-set intrusion detection system, OpenIDS, which addresses the problem through three modules: the MinMax autoencoder, the classifier, and the pseudo extreme value machine. The MinMax autoencoder maximizes the difference between the known malicious traffic and benign traffic and places unknown traffic in between. The deep classifier takes the basic traffic features and the discriminative traffic features extracted by the MinMax autoencoder as input to achieve the known intrusion detection. The completely modeled pseudo extreme value machine gets used to calibrate the penultimate layer activation of the classifier and then infers the unknown traffic by thresholding the calibrated scores. Experiments performed on datasets USTC-TFC2016 & CSE-CIC-IDS2018+ show that the proposed scheme is better than previously baseline models and can be effectively applied to realistic network environments.
What problem does this paper attempt to address?