A Lightweight Intrusion Detection System Using a Finite Dirichlet Mixture Model with Extended Stochastic Variational Inference

Yuping Lai,Yiying Yu,Wenbo Guan,Lijuan Luo,Jing Fan,Nanrun Zhou,Yuan Ping
DOI: https://doi.org/10.1109/tnsm.2024.3391250
2024-01-01
IEEE Transactions on Network and Service Management
Abstract:With the rapid development of the internet worldwide, network security issues are becoming increasingly prominent. Network intrusion detection systems (NIDSs) play a vital role in ensuring computer network security due to their ability to identify potential network threats. Despite considerable research efforts, deploying NIDSs on resource-constrained devices has been challenging. To reduce the imposed computational cost and model storage requirements, in this paper, we propose a novel lightweight NIDS model. In this model, patterns of normal and malicious actions are learned via a finite Dirichlet mixture model (DMM) in the context of the extended stochastic variational inference (ESVI) framework. With the proposed method, both the parameter estimation and model selection processes can be simultaneously addressed in a unified Bayesian framework. A great number of experiments conducted on three publicly available datasets demonstrate that the proposed model not only achieves comparable classification performance to that of detection models based on several well-studied finite mixture modeling, traditional machine learning (ML) and promising deep learning (DL) algorithms but also significantly reduces the required training and detection time. Extensive experimental results validate that the proposed model is a feasible and efficient lightweight intrusion detection model.
What problem does this paper attempt to address?