An active learning framework using deep Q-network for zero-day attack detection

Yali Wu,Yanghu Hu,Junhu Wang,Mengqi Feng,Ang Dong,Yanxi Yang
DOI: https://doi.org/10.1016/j.cose.2024.103713
IF: 5.105
2024-02-01
Computers & Security
Abstract:Zero-day attacks from highly dynamic and complex cyberspace make severe threats to the existing network intrusion detection systems. Robust and intelligent solutions are required to handle the rapidly evolving threats from internet environment. In this paper, a novel active learning framework based on Deep Q-Network (DQN) is proposed for zero-day attacks detection. The framework is composed of network intrusion detection systems classifier, sample selection strategy and annotator. Deep Q-Network model serves as an intelligent control component to select the zero-day samples for labeling with the probability distribution. Moreover, the Bi-directional Long Short-Term Memory (BiLSTM) network is integrated into DQN model to form the selecting policy to analyze the temporal correlation within the static classification context. Meanwhile, Euclidean distance function is adopted for labeling the selected samples to achieve an accurate labeling result. Two famous datasets named NSL_KDD and UNSW_NB15 in intrusion detection field are tested for evaluate the performance of our proposed framework. Compared to other machine learning methods, the approach proposed in this paper demonstrates better universality and generalizability . This indicates that the method is more capable of reliably identifying and detecting network intrusion behaviors, which holds significant importance for further security research and practical applications.
computer science, information systems
What problem does this paper attempt to address?