GE-IDS: an intrusion detection system based on grayscale and entropy

Dan Liao,Ruijin Zhou,Hui Li,Ming Zhang,Xue Chen
DOI: https://doi.org/10.1007/s12083-022-01300-z
2022-03-07
Abstract:An intrusion detection system (IDS) ensures cybersecurity. However, the existing IDSs face challenges, such as low detection accuracy, complex data feature extraction and high resource consumption costs. Therefore, this paper proposes an IDS based on grayscale and entropy, called the GE-IDS. The GE-IDS performs flow preprocessing based on filtering and grayscale conversion to realize traffic visualization. It improves real-time performance and reduces resource consumption. Moreover, the GE-IDS can effectively analyze and cluster traffic grayscales. On the basis of the obtained traffic grayscale clusters, the GE-IDS can detects known cyberattacks with a higher accuracy. By defining cluster entropy, the GE-IDS can detect unknown cyberattacks. We use the latest CICIIDS 2017 dataset to verify the performance of the GE-IDS. Simulation results show that the GE-IDS has high precision in terms of detecting known attacks. It also has a strong unknown attack detection ability.
computer science, information systems,telecommunications
What problem does this paper attempt to address?