A novel hierarchical attention-based triplet network with unsupervised domain adaptation for network intrusion detection

Jinghong Lan,Xudong Liu,Bo Li,Jun Zhao
DOI: https://doi.org/10.1007/s10489-022-04076-0
IF: 5.3
2022-09-10
Applied Intelligence
Abstract:Network Intrusion Detection Systems(NIDSs) are crucial for resisting cyber threats. However, NIDSs equipped with supervised learning models do not generalize well to unknown attacks because the training samples for previously unseen new intrusions are usually not available in advance. Thus, a new framework based on a H ierarchical A ttention-based T riplet network with U nsupervised D omain A daptation(HAT-UDA) is proposed for this purpose. Concretely, a joint loss is introduced to force HAT-UDA to learn compact and discriminative embeddings for benign network traffic while being far from the representations of known attacks. Then, a One-class Support Vector Machine(OCSVM) model is trained on top of the benign embeddings for the unknown attack detection task. Furthermore, we propose an unsupervised domain adaptation module in an adversarial manner to reduce the false positives of HAT-UDA when applied to new network scenarios. HAT-UDA provides a novel approach for building a robust NIDS from benign traffic and available (known) attacks. This is particularly meaningful since collecting samples for benign traffic and known attacks is much easier than obtaining instances for unseen new attacks. Extensive experiments show that HAT-UDA outperforms other state-of-the-art methods and significantly improves the detection rate of unknown attacks.
computer science, artificial intelligence
What problem does this paper attempt to address?