ILIDViz: an Incremental Learning-Based Visual Analysis System for Network Anomaly Detection

Xuefei Tian,Zhiyuan Wu,JunXiang Cao,Shengtao Chen,Xiaoju Dong
DOI: https://doi.org/10.1016/j.vrih.2023.06.009
2023-01-01
Virtual Reality & Intelligent Hardware
Abstract:Background With the development of information technology, there is a significant increase in the number of network traffic logs mixed with various types of cyberattacks. Traditional intrusion detection systems(IDSs) are limited in detecting new inconstant patterns and identifying malicious traffic traces in real time.Therefore, there is an urgent need to implement more effective intrusion detection technologies to protect computer security. Methods In this study, we designed a hybrid IDS by combining our incremental learning model(KANSOINN) and active learning to learn new log patterns and detect various network anomalies in real time. Conclusions Experimental results on the NSLKDD dataset showed that KAN-SOINN can be continuously improved and effectively detect malicious logs. Meanwhile, comparative experiments proved that using a hybrid query strategy in active learning can improve the model learning efficiency.
What problem does this paper attempt to address?